CVE-2024-25654

MEDIUM

Avsystem Unified Management Platform - Log Information Exposure

Title source: rule
STIX 2.1

Description

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 6.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532 CWE-276
Status published
Products (1)
avsystem/unified_management_platform 23.07.0.16567
Published Mar 18, 2024
Tracked Since Feb 18, 2026