CVE-2024-25655

MEDIUM

AVSystem UMP 23.07.0.16567~LTS - Info Disclosure

Title source: llm
STIX 2.1

Description

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-922
Status published
Published Mar 18, 2024
Tracked Since Feb 18, 2026