Desktop Alert

A Directory Traversal vulnerability was found in the Application Server of Desktop Alert version 6.1.0.11 to 6.1.1.5 which allows an attacker to write arbitrary files under certain conditions.

Vulnerability Type (CWE-22) Directory Traversal 
CVE Identifier CVE-2025-54347
CVSS Score 9.9
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Vendor Desktop Alert
Affected Product PingAlert Application Server
Affected Versions 6.1.0.11 – 6.1.1.5
Attacker Authenticated user
Impact Arbitrary files could be uploaded
Mitigation Fixed in version 6.1.1.6

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.

 

Desktop Alert