Записи smarsh
8 опубликованных записей вендора smarsh.
Профиль для исследователя
- Попали в KEV
- 2 · 25 %
- С эксплойтом
- 2 · 25 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 34 дн.
Повторяющиеся классы
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-316 Cleartext Storage of Sensitive Information in Memory1
- CWE-328 Use of Weak Hash1
- CWE-528 Exposure of Core Dump File to an Unauthorized Control Sphere1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2025-48927Готовый эксплойт | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploitsmarsh · telemessage · CWE-1188 | Средняя5,3 | KEV | 11,1 % | 28 мая 2025 г. |
46В плане | CVE-2025-48928Готовый эксплойт | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" insmarsh · telemessage · CWE-528 | Средняя4,0 | KEV | 0,6 % | 28 мая 2025 г. |
39Наблюдать | CVE-2025-48929Эксплойта нет | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiratsmarsh · telemessage · CWE-922 | Критическая9,8 | — | 0,3 % | 28 мая 2025 г. |
30Наблюдать | CVE-2025-47730Эксплойта нет | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Sismarsh · telemessage · CWE-798 | Высокая7,5 | — | 0,4 % | 8 мая 2025 г. |
30Наблюдать | CVE-2025-48925Эксплойта нет | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash assmarsh · telemessage · CWE-836 | Высокая7,5 | — | 0,3 % | 28 мая 2025 г. |
30Наблюдать | CVE-2025-48926Эксплойта нет | The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telepsmarsh · telemessage · CWE-288 | Высокая7,5 | — | 0,3 % | 28 мая 2025 г. |
22Наблюдать | CVE-2025-48931Эксплойта нет | The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbosmarsh · telemessage · CWE-328 | Средняя5,5 | — | 0,1 % | 28 мая 2025 г. |
21Наблюдать | CVE-2025-48930Эксплойта нет | The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to asmarsh · telemessage · CWE-316 | Средняя5,3 | — | 0,1 % | 28 мая 2025 г. |
- CVE-2025-4892754В плане
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 11 %smarsh · telemessage28 мая 2025 г.
- CVE-2025-4892846В плане
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in
СредняяCVSS 4,0KEVГотовый эксплойтEPSS 1 %smarsh · telemessage28 мая 2025 г.
- CVE-2025-4892939Наблюдать
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.
- CVE-2025-4773030Наблюдать
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Si
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %smarsh · telemessage8 мая 2025 г.
- CVE-2025-4892530Наблюдать
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.
- CVE-2025-4892630Наблюдать
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telep
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.
- CVE-2025-4893122Наблюдать
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbo
СредняяCVSS 5,5Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.
- CVE-2025-4893021Наблюдать
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to a
СредняяCVSS 5,3Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.