go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

aEnrich Technology a+HRD - Exposure of Sensitive Data

TVN ID TVN-202404001
CVE ID CVE-2024-3774
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products aEnrich Technology a+HRD 6.8, 7.0, 7.1, 7.2
Description aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
Solution Update to eHRD 6.8.1039V1055 or later version
Update to eHRD 7.0.1141V422 or later version
Update to eHRD 7.1.1033V429 or later version
Update to eHRD 7.2.1061V36 or later version
Credit Cyku(DEVCORE)
Public Date 2024-04-15
Top