CVE-2025-0584: aEnrich Technology a+HRD - Server-Side Request Forgery (SSRF)
Published Jan 20, 2025
·Updated
The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
Affected Software
2 affected components
aEnrich Technology a+HRD
aEnrich A\+hrd<=7.5
Remediation
Information
Please refer to the aEnrich advisory to upgrade to version 6.8 or later and install the latest patches, or contact aEnrich customer service for assistance.
Event History
Jan 20, 2025
CVE Published
via MITRE·02:06 AM
Data Sourced
via MITRE·02:06 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0584?
CVE-2025-0584 is classified as a critical severity vulnerability due to the potential for unauthenticated remote exploitation.
2
How do I fix CVE-2025-0584?
To fix CVE-2025-0584, update your a+HRD application to the latest patched version provided by aEnrich Technology.
3
What type of vulnerability is CVE-2025-0584?
CVE-2025-0584 is a Server-side Request Forgery (SSRF) vulnerability.
4
Who is affected by CVE-2025-0584?
CVE-2025-0584 affects users of a+HRD from aEnrich Technology.
5
What can attackers do with CVE-2025-0584?
Attackers can use CVE-2025-0584 to probe internal networks and potentially access sensitive resources.