CVE-2024-25656

MEDIUM

AVSystem UMP 23.07.0.16567~LTS - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipment) devices storing arbitrarily large amounts of data during registration. This can potentially lead to DDoS attacks on the application database and, ultimately, affect the entire product.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0046
EPSS Percentile 36.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Published Mar 18, 2024
Tracked Since Feb 18, 2026