Desktop Alert

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm.

Vulnerability Type (CWE-327) Use of a Broken or Risky Cryptographic Algorithm
CVE Identifier CVE-2025-54340
CVSS Score 4.1
CVSS Vector (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N)
Vendor Desktop Alert
Affected Product PingAlert Application Server
Affected Versions 6.1.0.11 – 6.1.1.2
Attacker Non-authenticated user 
Impact Potential recovery of protected passwords
Mitigation Fixed in version 6.1.1.4

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.

 

Desktop Alert