We’d love your feedback! Only 3 short questions and 5 min of your time. Take the short survey →

Security Advisories: CVE-2025-54561

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert version 6.1.0.11 to 6.1.1.4 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema

Vulnerability Type(CWE-284) Incorrect Access Control
CVE IdentifierCVE-2025-54561
CVSS Score7.6
CVSS Vector(CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L)
VendorDesktop Alert
Affected ProductPingAlert Application Server
Affected Versions6.1.0.11 – 6.1.1.4
AttackerAny unauthenticated user
ImpactIt allows remote access to content despite lack of the correct permission.
MitigationFixed in version 6.1.1.5

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.