CVE-2024-25655

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
Configurations

No configuration.

History

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25655 - () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25655 -

28 Aug 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-922

19 Mar 2024, 13:26

Type Values Removed Values Added
Summary
  • (es) El almacenamiento inseguro de contraseñas LDAP en la funcionalidad de autenticación de AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS permite a los miembros (con acceso de lectura a la base de datos de la aplicación) descifrar las contraseñas LDAP de los usuarios que se autentican exitosamente en la administración web a través de LDAP.

18 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 20:15

Updated : 2024-11-21 09:01


NVD link : CVE-2024-25655

Mitre link : CVE-2024-25655

CVE.ORG link : CVE-2024-25655


JSON object : View

Products Affected

No product.

CWE
CWE-922

Insecure Storage of Sensitive Information