cve/2024/CVE-2024-25654.md
2024-05-25 21:48:12 +02:00

719 B

CVE-2024-25654

Description

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.

POC

Reference

No PoCs from references.

Github