CVE-2022-39042: aEnrich a+HRD - Improper Authentication
Published Jan 3, 2023
·Updated
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
Affected Software
2 affected components
aEnrich A\+hrd=6.8
aEnrich A\+hrd=7.0
Event History
Jan 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-39042.
2
What is the severity level of CVE-2022-39042?
The severity level of CVE-2022-39042 is critical with a CVSS score of 9.8.
3
What software versions are affected by CVE-2022-39042?
Versions 6.8 and 7.0 of Aenrich A+hrd are affected by CVE-2022-39042.
4
How can an attacker exploit CVE-2022-39042?
An unauthenticated remote attacker can exploit CVE-2022-39042 to bypass authentication and access API function to perform arbitrary system commands or disrupt service.
5
Is there a fix available for CVE-2022-39042?
Please refer to the vendor's website or official sources for information on available fixes or patches for CVE-2022-39042.