Skip to content
Noroxi

smarsh records

8 published records for vendor smarsh.

Researcher profile

Entered KEV
2 · 25%
Weaponized
2 · 25%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
34 days

All records

8 records
  • The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit

    MediumCVSS 5.3KEVWeaponizedEPSS 11%

    smarsh · telemessageMay 28, 2025

  • The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in

    MediumCVSS 4.0KEVWeaponizedEPSS 1%

    smarsh · telemessageMay 28, 2025

  • The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat

    CriticalCVSS 9.8No exploitEPSS 0%

    smarsh · telemessageMay 28, 2025

  • The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Si

    HighCVSS 7.5No exploitEPSS 0%

    smarsh · telemessageMay 8, 2025

  • The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as

    HighCVSS 7.5No exploitEPSS 0%

    smarsh · telemessageMay 28, 2025

  • The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telep

    HighCVSS 7.5No exploitEPSS 0%

    smarsh · telemessageMay 28, 2025

  • The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbo

    MediumCVSS 5.5No exploitEPSS 0%

    smarsh · telemessageMay 28, 2025

  • The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to a

    MediumCVSS 5.3No exploitEPSS 0%

    smarsh · telemessageMay 28, 2025