Перейти к содержимому
Noroxi

Записи smarsh

8 опубликованных записей вендора smarsh.

Профиль для исследователя

Попали в KEV
2 · 25 %
С эксплойтом
2 · 25 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
34 дн.

Записи по годам

  1. 25

Столбик: всего · тёмная часть: CISA KEV.

Все записи

8 записей
  • CVE-2025-48927
    54В плане

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit

    СредняяCVSS 5,3KEVГотовый эксплойтEPSS 11 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2025-48928
    46В плане

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in

    СредняяCVSS 4,0KEVГотовый эксплойтEPSS 1 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2025-48929
    39Наблюдать

    The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2025-47730
    30Наблюдать

    The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Si

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    smarsh · telemessage8 мая 2025 г.

  • CVE-2025-48925
    30Наблюдать

    The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2025-48926
    30Наблюдать

    The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telep

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2025-48931
    22Наблюдать

    The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbo

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2025-48930
    21Наблюдать

    The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to a

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.