ZeroHour

CVE-2024-25654

PoC
CVSS 3.1
5.5 medium
EPSS
<1%p12
Published
()
Modified
Description

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.

Vendors
avsystem
Products
unified management platform
Weakness
CWE-532, CWE-276
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.