CVE-2024-25654

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 Exploit Third Party Advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:avsystem:unified_management_platform:23.07.0.16567:*:*:*:lts:*:*:*

History

14 Mar 2025, 01:15

Type Values Removed Values Added
CPE cpe:2.3:a:avsystem:unified_management_platform:23.07.0.16567:*:*:*:lts:*:*:*
References () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 - () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 - Exploit, Third Party Advisory
CWE CWE-532
CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Avsystem unified Management Platform
Avsystem

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 - () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 -

18 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 20:15

Updated : 2025-03-14 01:15


NVD link : CVE-2024-25654

Mitre link : CVE-2024-25654

CVE.ORG link : CVE-2024-25654


JSON object : View

Products Affected

avsystem

  • unified_management_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-276

Incorrect Default Permissions