CVE-2024-25654: Avsystem Unified Management Platform
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
Affected products
- Avsystem Unified Management Platform: version 23.07.0.16567 only
Published 2024-03-18. Last modified 2026-06-17.