CVE-2023-20852
CRITICALAenrich A+hrd - Insecure Deserialization
Title source: ruleDescription
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
Scores
CVSS v3
9.8
EPSS
0.0067
EPSS Percentile
71.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
aenrich/a\+hrd
Timeline
Published
Apr 27, 2023
Tracked Since
Feb 18, 2026