An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data.
This issue affects Asseco mMedica in versions before 11.9.5.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mmedica
Mmedica mmedica |
|
| Vendors & Products |
Mmedica
Mmedica mmedica |
Tue, 28 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data. This issue affects Asseco mMedica in versions before 11.9.5. | |
| Title | Unauthorized database access in Asseco mMedica | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-10-28T13:15:31.459Z
Reserved: 2025-08-21T07:29:05.144Z
Link: CVE-2025-9313
Updated: 2025-10-28T13:15:24.252Z
Status : Received
Published: 2025-10-28T12:15:42.967
Modified: 2025-10-28T12:15:42.967
Link: CVE-2025-9313
No data.