We’d love your feedback! Only 3 short questions and 5 min of your time. Take the short survey →

Security Advisories: CVE-2025-54340

A vulnerability was found in the Application Server of Desktop Alert version 6.1.0.11 to 6.1.1.3. There is a Broken or Risky Cryptographic Algorithm.

Vulnerability Type(CWE-327) Use of a Broken or Risky Cryptographic Algorithm
CVE IdentifierCVE-2025-54340
CVSS Score4.1
CVSS Vector(CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N)
VendorDesktop Alert
Affected ProductPingAlert Application Server
Affected Versions6.1.0.11 – 6.1.1.3
AttackerNon-authenticated user 
ImpactPotential recovery of protected passwords
MitigationFixed in version 6.1.1.4

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.