CVE-2025-54341
BaseFortify
Publication date: 2025-11-24
Last updated on: 2025-12-05
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| desktopalert | pingalert_application_server | From 6.1.0.11 (inc) to 6.1.1.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves hard-coded configuration values in the Application Server of Desktop Alert PingAlert versions 6.1.0.11 to 6.1.1.2. Hard-coded values can lead to security risks because they may expose sensitive information or reduce the ability to properly configure security settings.
How can this vulnerability impact me? :
The vulnerability can impact you by potentially exposing sensitive configuration details, which could be exploited by attackers to gain unauthorized access or reduce the security posture of the affected system. The CVSS score of 5.3 indicates a moderate severity with potential confidentiality impact but no impact on integrity or availability.