Desktop Alert

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert version 6.1.0.11 to 6.1.1.5 which allows Incorrect Access Control, leading to Remote Information Disclosure.

Vulnerability Type (CWE-284) Incorrect Access Control
CVE Identifier CVE-2025-54563
CVSS Score 5.3
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Vendor Desktop Alert
Affected Product PingAlert Application Server
Affected Versions 6.1.0.11 – 6.1.1.5
Attacker Any unauthenticated user
Impact It has Incorrect Access Control, leading to Remote Information Disclosure.
Mitigation Fixed in version 6.1.1.6

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.

 

Desktop Alert