CVE-2025-12870: aEnrich|eHRD - Authentication Abuse
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12870?
CVE-2025-12870 is considered a critical vulnerability due to its potential to grant unauthorized access to administrative privileges.
How do I fix CVE-2025-12870?
To fix CVE-2025-12870, ensure that your aEnrich eHRD software is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-12870?
Any users of the aEnrich eHRD software are potentially affected by CVE-2025-12870.
What type of attack does CVE-2025-12870 enable?
CVE-2025-12870 enables unauthenticated remote attackers to gain administrator access tokens through crafted packets.
What is the potential impact of CVE-2025-12870?
The potential impact of CVE-2025-12870 includes unauthorized access to system functionality and data with elevated privileges.