ZeroHour

CVE-2022-39042

CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.

Vendors
aenrich
Products
a\+hrd
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.