CVE-2024-25654

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 Exploit Third Party Advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:avsystem:unified_management_platform:23.07.0.16567:*:*:*:lts:*:*:*

History

14 Mar 2025, 01:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:avsystem:unified_management_platform:23.07.0.16567:*:*:*:lts:*:*:*
CWE CWE-276
CWE-532
References () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 - () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 - Exploit, Third Party Advisory
First Time Avsystem
Avsystem unified Management Platform

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 - () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25654 -

19 Mar 2024, 13:26

Type Values Removed Values Added
Summary
  • (es) Los permisos inseguros para archivos de registro de AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS permiten a los miembros (con acceso local al servidor de aplicaciones UMP) acceder a las credenciales para autenticarse en todos los servicios y descifrar datos confidenciales almacenados en la base de datos.

18 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 20:15

Updated : 2025-03-14 01:15


NVD link : CVE-2024-25654

Mitre link : CVE-2024-25654

CVE.ORG link : CVE-2024-25654


JSON object : View

Products Affected

avsystem

  • unified_management_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-276

Incorrect Default Permissions