CVE-2025-54338
7.5Desktop Alert · PingAlert
Desktop Alert PingAlert contains an incorrect access control vulnerability in the application server that allows unauthenticated remote attackers to disclose sensitive user hashes.
Executive summary
A critical access control flaw in Desktop Alert PingAlert version 6.1.0.11 through 6.1.1.2 permits unauthenticated disclosure of user hashes, posing a significant risk of credential compromise.
Vulnerability
This vulnerability is an incorrect access control flaw within the application server. It allows an unauthenticated attacker to remotely access and disclose sensitive user hashes from the system.
Business impact
The exposure of user hashes can lead to unauthorized account access if attackers successfully crack the retrieved credentials. Given the CVSS score of 7.5, this vulnerability represents a high risk, as it facilitates unauthorized data exfiltration that could result in broader system compromise or unauthorized access to internal resources.
Remediation
Immediate Action: Contact the vendor, Desktop Alert, to obtain the necessary security update or configuration guidance, as a specific patch version is not currently documented.
Proactive Monitoring: Review application server access logs for unusual patterns or frequent unauthorized requests directed at user data endpoints.
Compensating Controls: Implement strict network access controls to restrict traffic to the application server and deploy a Web Application Firewall to detect and block malicious requests attempting to exploit access control mechanisms.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing the affected versions of PingAlert should prioritize this issue due to the potential for credential harvesting. Until an official patch is verified and applied, administrators must restrict network exposure of the vulnerable application server to minimize the attack surface.