CVE-2024-25654

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 Exploit Third Party Advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:avsystem:unified_management_platform:23.07.0.16567:*:*:*:lts:*:*:*

History

No history.

Information

Published : 2024-03-18 20:15

Updated : 2025-03-14 01:15


NVD link : CVE-2024-25654

Mitre link : CVE-2024-25654

CVE.ORG link : CVE-2024-25654


JSON object : View

Products Affected

avsystem

  • unified_management_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-276

Incorrect Default Permissions