Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25655 |
|
History
Wed, 28 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-922 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-18T00:00:00
Updated: 2024-08-28T15:44:55.431Z
Reserved: 2024-02-09T00:00:00
Link: CVE-2024-25655
Updated: 2024-08-01T23:52:04.899Z
Status : Awaiting Analysis
Published: 2024-03-18T20:15:08.917
Modified: 2024-11-21T09:01:10.503
Link: CVE-2024-25655
No data.