Database Access Vulnerability in Asseco mMedica Software
CVE-2025-9313

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
28 October 2025

What is CVE-2025-9313?

An unauthenticated user can exploit a flaw in Asseco mMedica software to connect to a publicly accessible database using arbitrary credentials. This vulnerability arises from a misconfigured authentication mechanism within the 'mmBackup' application, enabling malicious users to bypass standard security protocols. By leveraging this issue, attackers are granted full access to the database, potentially exposing sensitive information and putting data integrity at risk.

Affected Version(s)

mMedica 0 < 11.9.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.