Description
The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.
Published: 2024-10-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Please contact Sunnet for version updates or upgrades.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-33120 The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.
History

Thu, 25 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sun.net ehrd Ctms
CPEs cpe:2.3:a:sun.net:ehdr_ctms:*:*:*:*:*:*:*:* cpe:2.3:a:sun.net:ehrd_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sun.net ehdr Ctms
Sun.net ehrd Ctms

Thu, 31 Oct 2024 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Sun.net
Sun.net ehdr Ctms
CPEs cpe:2.3:a:sun.net:ehdr_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sun.net
Sun.net ehdr Ctms

Mon, 28 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Sunnet
Sunnet ehrd Ctms
CPEs cpe:2.3:a:sunnet:ehrd_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sunnet
Sunnet ehrd Ctms
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Oct 2024 03:15:00 +0000

Type Values Removed Values Added
Description The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.
Title Sunnet eHRD CTMS - Authentication Bypass
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Sun.net Ehrd Ctms
Sunnet Ehrd Ctms
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-28T12:52:28.130Z

Reserved: 2024-10-28T02:02:16.992Z

Link: CVE-2024-10438

cve-icon Vulnrichment

Updated: 2024-10-28T12:52:21.855Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-28T03:15:02.423

Modified: 2025-09-25T14:13:08.880

Link: CVE-2024-10438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses