CVE-2024-25657
- EPSS 0.08%
- Veröffentlicht 18.03.2024 20:15:09
- Zuletzt bearbeitet 21.11.2024 09:01:10
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to malicious websites.
CVE-2024-25654
- EPSS 0.03%
- Veröffentlicht 18.03.2024 20:15:08
- Zuletzt bearbeitet 14.03.2025 01:15:38
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data st...
CVE-2024-25655
- EPSS 0.09%
- Veröffentlicht 18.03.2024 20:15:08
- Zuletzt bearbeitet 21.11.2024 09:01:10
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successful...
CVE-2024-25656
- EPSS 0.09%
- Veröffentlicht 18.03.2024 20:15:08
- Zuletzt bearbeitet 21.11.2024 09:01:10
Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipment) devices storing arbitrarily large amounts of data during registration. This can potentially lead...