CVE-2024-25655: Avsystem Unified Management Platform
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
Affected products
- Avsystem Unified Management Platform: version 23.07.0.16567 only
Published 2024-03-18. Last modified 2026-06-17.