smarsh records
8 published records for vendor smarsh.
Researcher profile
- Entered KEV
- 2 · 25%
- Weaponized
- 2 · 25%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- 34 days
Recurring classes
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-316 Cleartext Storage of Sensitive Information in Memory1
- CWE-328 Use of Weak Hash1
- CWE-528 Exposure of Core Dump File to an Unauthorized Control Sphere1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2025-48927Weaponized | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploitsmarsh · telemessage · CWE-1188 | Medium5.3 | KEV | 11.1% | May 28, 2025 |
46Plan | CVE-2025-48928Weaponized | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" insmarsh · telemessage · CWE-528 | Medium4.0 | KEV | 0.6% | May 28, 2025 |
39Monitor | CVE-2025-48929No exploit | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiratsmarsh · telemessage · CWE-922 | Critical9.8 | — | 0.3% | May 28, 2025 |
30Monitor | CVE-2025-47730No exploit | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Sismarsh · telemessage · CWE-798 | High7.5 | — | 0.4% | May 8, 2025 |
30Monitor | CVE-2025-48925No exploit | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash assmarsh · telemessage · CWE-836 | High7.5 | — | 0.3% | May 28, 2025 |
30Monitor | CVE-2025-48926No exploit | The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telepsmarsh · telemessage · CWE-288 | High7.5 | — | 0.3% | May 28, 2025 |
22Monitor | CVE-2025-48931No exploit | The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbosmarsh · telemessage · CWE-328 | Medium5.5 | — | 0.1% | May 28, 2025 |
21Monitor | CVE-2025-48930No exploit | The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to asmarsh · telemessage · CWE-316 | Medium5.3 | — | 0.1% | May 28, 2025 |
- CVE-2025-4892754Plan
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit
MediumCVSS 5.3KEVWeaponizedEPSS 11%smarsh · telemessageMay 28, 2025
- CVE-2025-4892846Plan
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in
MediumCVSS 4.0KEVWeaponizedEPSS 1%smarsh · telemessageMay 28, 2025
- CVE-2025-4892939Monitor
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat
CriticalCVSS 9.8No exploitEPSS 0%smarsh · telemessageMay 28, 2025
- CVE-2025-4773030Monitor
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Si
HighCVSS 7.5No exploitEPSS 0%smarsh · telemessageMay 8, 2025
- CVE-2025-4892530Monitor
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as
HighCVSS 7.5No exploitEPSS 0%smarsh · telemessageMay 28, 2025
- CVE-2025-4892630Monitor
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telep
HighCVSS 7.5No exploitEPSS 0%smarsh · telemessageMay 28, 2025
- CVE-2025-4893122Monitor
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbo
MediumCVSS 5.5No exploitEPSS 0%smarsh · telemessageMay 28, 2025
- CVE-2025-4893021Monitor
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to a
MediumCVSS 5.3No exploitEPSS 0%smarsh · telemessageMay 28, 2025