Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 9 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.

CWE-328May 28, 2025
CVSS3.2v3.1EPSS0.081%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Cleartext Storage of Sensitive Information in Memory

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

CWE-316May 28, 2025
CVSS2.8v3.1EPSS0.115%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

CWE-1188May 28, 2025
CVSS5.3v3.1EPSS9.07%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Authentication Bypass Using an Alternate Path or Channel

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

CWE-288May 28, 2025
CVSS4.3v3.1EPSS0.216%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

CWE-528CWE-552May 28, 2025
CVSS4.0v3.1EPSS0.408%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Use of Password Hash Instead of Password for Authentication

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.

CWE-836May 28, 2025
CVSS4.3v3.1EPSS0.233%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Insecure Storage of Sensitive Information

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

CWE-613CWE-922May 28, 2025
CVSS4.0v3.1EPSS0.282%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Use of Hard-coded Credentials

The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.

CWE-798May 8, 2025
CVSS4.8v3.1EPSS0.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Hidden Functionality Vulnerability

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.

CWE-912May 8, 2025
CVSS1.9v3.1EPSS0.428%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX