Unified Management Platform
Avsystem · 4 CVEs
CVE-2024-25657
MEDIUM
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.0…
Mar 18, 2024
CVE-2024-25656
MEDIUM
Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated…
Mar 18, 2024
CVE-2024-25655
MEDIUM
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23…
Mar 18, 2024
CVE-2024-25654
MEDIUM
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with…
Mar 18, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-25657 | An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to r… | MEDIUM | 0.32% | Mar 18, 2024 |
| CVE-2024-25656 | Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipment) devic… | MEDIUM | 0.46% | Mar 18, 2024 |
| CVE-2024-25655 | Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with rea… | MEDIUM | 0.46% | Mar 18, 2024 |
| CVE-2024-25654 | Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application serv… | MEDIUM | 0.21% | Mar 18, 2024 |
Showing 1 to 4 of 4 CVEs