CVE-2025-31512
7.3AlertEnterprise · Guardian
A vulnerability in AlertEnterprise Guardian 4.1.14.2.2.1 allows unauthenticated attackers to bypass mandatory manager approval workflows via the Request Building Access API.
Executive summary
An unauthenticated bypass vulnerability in AlertEnterprise Guardian allows unauthorized request approval, posing a significant risk to physical security and access control integrity.
Vulnerability
The flaw resides in the Request Building Access API where the isAddedByApprover parameter can be manipulated to bypass required manager approval. This vulnerability is exploitable by an unauthenticated attacker via a crafted API call.
Business impact
The ability to bypass manager approvals for building access requests poses a direct threat to organizational security and compliance. With a CVSS score of 7.3, this high-severity flaw could allow unauthorized personnel to gain physical access to restricted areas without oversight, potentially leading to theft, sabotage, or severe breaches of safety protocols.
Remediation
Immediate Action: Update the AlertEnterprise Guardian installation to a build number equal to or greater than 4.1.12.2.1.19, 4.1.12.5.2.36, 4.1.13.0.60, 4.1.13.2.0.3.39, 4.1.13.2.0.3.41, 4.1.13.2.42, 4.1.13.2.25.44, 4.1.14.0.13, 4.1.14.0.43, 4.1.14.0.48, or 4.1.14.1.5.32.
Proactive Monitoring: Review access request logs for suspicious or high-volume API activity, specifically focusing on requests where manager approval appears to have been bypassed or system-automated without appropriate authorization.
Compensating Controls: If immediate patching is not feasible, implement strict network-level access controls to restrict access to the affected API endpoints to trusted internal IP ranges only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for unauthorized physical access, organizations using AlertEnterprise Guardian must prioritize applying the vendor-provided build updates. Ensure that all affected systems are brought up to the specified secure versions immediately to eliminate the risk of approval bypass.