İçeriğe atla
Noroxi

smarsh kayıtları

smarsh üreticisine ait 8 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
2 · %25
Silahlaştırılmış
2 · %25
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
34 gün

Tüm kayıtlar

8 kayıt
  • CVE-2025-48927
    54Planlayın

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %11

    smarsh · telemessage28 May 2025

  • CVE-2025-48928
    46Planlayın

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in

    OrtaCVSS 4,0KEVSilahlaştırılmışEPSS %1

    smarsh · telemessage28 May 2025

  • CVE-2025-48929
    39İzleyin

    The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat

    KritikCVSS 9,8İstismar yokEPSS %0

    smarsh · telemessage28 May 2025

  • CVE-2025-47730
    30İzleyin

    The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Si

    YüksekCVSS 7,5İstismar yokEPSS %0

    smarsh · telemessage8 May 2025

  • CVE-2025-48925
    30İzleyin

    The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as

    YüksekCVSS 7,5İstismar yokEPSS %0

    smarsh · telemessage28 May 2025

  • CVE-2025-48926
    30İzleyin

    The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telep

    YüksekCVSS 7,5İstismar yokEPSS %0

    smarsh · telemessage28 May 2025

  • CVE-2025-48931
    22İzleyin

    The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbo

    OrtaCVSS 5,5İstismar yokEPSS %0

    smarsh · telemessage28 May 2025

  • CVE-2025-48930
    21İzleyin

    The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to a

    OrtaCVSS 5,3İstismar yokEPSS %0

    smarsh · telemessage28 May 2025