The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
Fixes

Solution

Please refer to the aEnrich advisory to upgrade to version 6.8 or later and install the latest patches, or contact aEnrich customer service for assistance.


Workaround

No workaround given by the vendor.

History

Tue, 21 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jan 2025 02:30:00 +0000

Type Values Removed Values Added
Description The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
Title aEnrich Technology a+HRD - Server-Side Request Forgery (SSRF)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-01-21T14:43:40.739Z

Reserved: 2025-01-20T01:32:29.294Z

Link: CVE-2025-0584

cve-icon Vulnrichment

Updated: 2025-01-21T14:43:29.815Z

cve-icon NVD

Status : Received

Published: 2025-01-20T03:15:09.120

Modified: 2025-01-20T03:15:09.120

Link: CVE-2025-0584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.