PT-2025-44151 · Asseco · Asseco Mmedica

Published

2025-10-28

·

Updated

2025-10-28

·

CVE-2025-9313

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Asseco mMedica versions prior to 11.9.5
Description An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through the mmBackup application. This allows attackers to bypass authentication mechanisms and gain unauthorized access to sensitive data within the database.
Recommendations Update Asseco mMedica to version 11.9.5 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-9313

Affected Products

Asseco Mmedica