avsystem records
4 published records for vendor avsystem.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-922 Insecure Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2024-25655No exploit | Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allowCWE-922 | Medium6.5 | — | 0.5% | Mar 18, 2024 |
23Monitor | CVE-2024-25656No exploit | Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer PremisCWE-20 | Medium5.9 | — | 0.5% | Mar 18, 2024 |
22Monitor | CVE-2024-25654No exploit | Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the Uavsystem · unified management platform · CWE-532 | Medium5.5 | — | 0.2% | Mar 18, 2024 |
21Monitor | CVE-2024-25657No exploit | An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could aCWE-601 | Medium5.4 | — | 0.3% | Mar 18, 2024 |
- CVE-2024-2565526Monitor
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow
MediumCVSS 6.5No exploitEPSS 0%Mar 18, 2024
- CVE-2024-2565623Monitor
Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premis
MediumCVSS 5.9No exploitEPSS 0%Mar 18, 2024
- CVE-2024-2565422Monitor
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the U
MediumCVSS 5.5No exploitEPSS 0%avsystem · unified management platformMar 18, 2024
- CVE-2024-2565721Monitor
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could a
MediumCVSS 5.4No exploitEPSS 0%Mar 18, 2024