Home/Product/smarsh telemessage
Product

smarsh telemessage

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-48931
<= 2025-05-05
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (includ
3.2LOW
CVE-2025-48930
<= 2025-05-05
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be acces
2.8LOW
CVE-2025-48929
<= 2025-05-05
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a sho
4.0MEDIUM
CVE-2025-48928
all versions
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "cor
4.0MEDIUM
CVE-2025-48927
all versions
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI,
5.3MEDIUM
CVE-2025-48926
<= 2025-05-05
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords,
4.3MEDIUM
CVE-2025-48925
<= 2025-05-05
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts t
4.3MEDIUM
CVE-2025-47730
<= 2025-05-05
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka
4.8MEDIUM
CVE-2025-47729
<= 2025-05-05
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app user
1.9LOW
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin