CVE-2024-25654

MEDIUM

AVSystem Unified Management Platform 23.07.0.16567~LTS - Sensitive Information Exposure via Log File Permissions

Title source: llm
STIX 2.1

Description

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532 CWE-276
Status published
Products (1)
avsystem/unified_management_platform 23.07.0.16567
Published Mar 18, 2024
Tracked Since Feb 18, 2026