# DOS SS1 asset manager has eight flaws

Published: 2025-08-26 · Severity: medium
Canonical: https://vorant.io/reports/30127bc3-8966-51f2-86ae-1ef1c197c373/dos-ss1-asset-manager-has-eight-flaws

> SS1 asset-management software from DOS Corporation has eight vulnerabilities, including two critical (CVSS 9.8) file-upload validation flaws, with patches now available.

Japan's IPA published a JVN advisory detailing eight vulnerabilities in SS1, an IT asset-management tool from DOS Corporation, and its cloud variant. The flaws span weak cryptographic strength, externally accessible files/directories, improper access-control assignment, insufficient upload file validation, path traversal, and a hardcoded password. The two most severe issues (CVE-2025-53970 and CVE-2025-54762, CVSS 9.8) stem from insufficient upload validation on the Windows client and could allow a remote, unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

Other vulnerabilities allow remote access to authentication-gated functionality, exposure of uploaded files or SS1 configuration data, overwriting of legitimate files, and arbitrary file disclosure — in one MacOS-specific case with root privileges. A locally logged-in client user could also exploit some flaws to escalate to root. Several vulnerabilities are platform-specific: three affect only Windows environments and three affect only MacOS environments. Affected versions are SS1 up to Ver.16.0.0.10 (media version 16.0.0a and earlier) and SS1 Cloud up to Ver.2.1.3.

No evidence of active exploitation is presented in the advisory; it is a coordinated disclosure urging administrators to update to the vendor's latest patched release. IPA recommends organizations running SS1 apply available updates promptly given the presence of unauthenticated, remotely exploitable critical-severity issues.

## Mentioned in this report

- Vulnerabilities: CVE-2025-46409, CVE-2025-52460, CVE-2025-53396, CVE-2025-53970, CVE-2025-54762, CVE-2025-54819, CVE-2025-58072, CVE-2025-58081

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20250827-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/30127bc3-8966-51f2-86ae-1ef1c197c373/dos-ss1-asset-manager-has-eight-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
