CVE-2025-54345

7.5

Desktop Alert · PingAlert

Desktop Alert PingAlert versions 6.1.0.11 through 6.1.1.2 contain a vulnerability in the Application Server that allows unauthorized actors to access sensitive information.

Executive summary

A sensitive information disclosure vulnerability in Desktop Alert PingAlert 6 allows unauthenticated remote attackers to access restricted data.

Vulnerability

The application server fails to properly restrict access to sensitive resources, allowing an unauthenticated attacker to retrieve information over the network without requiring valid credentials.

Business impact

This vulnerability carries a CVSS score of 7.5, indicating a high severity risk that could lead to significant data breaches. Unauthorized exposure of sensitive information may result in the loss of intellectual property, exposure of user credentials, or the leakage of configuration data that facilitates further network compromise. Organizations utilizing affected versions of PingAlert face immediate risks to data confidentiality and regulatory compliance.

Remediation

Immediate Action: Contact the vendor immediately via their official support portal to obtain the relevant security hotfix or configuration guidance for PingAlert version 6.

Proactive Monitoring: Review web server and application access logs for unusual patterns of requests directed at administrative or sensitive endpoints, particularly those originating from unauthorized network segments.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and block suspicious traffic patterns targeting the PingAlert application server until a formal patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the information disclosure, administrators should prioritize this issue within their vulnerability management lifecycle. While a specific patch version is currently not public, organizations must engage with the vendor immediately to secure their environments against unauthorized access.

More Desktop Alert CVEs

Sources