216.73.217.22

CVE-2025-9313

· Published 28/10/2025 12:15 · Modified 28/10/2025 12:15

Labels: CVE-2025-9313 2025-10-28CVE-2025-9313CWE-288[email protected]

Essential information

Published
28/10/2025 12:15
Modified
28/10/2025 12:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data. This issue affects Asseco mMedica in versions before 11.9.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
asseco / medica cpe:2.3:a:asseco:medica:<11.9.5:*:*:*:*:*:*:*

References