Showing 8 vulnerabilities on this page for TM SGNL

Signals CISA KEV Ransomware Nuclei
TeleMessage vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

smarsh telemessage Cleartext Storage of Sensitive Information in Memory

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

CWE-316May 28, 2025
CVSS2.8v3.1EPSS0.115%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

CWE-1188May 28, 2025
CVSS5.3v3.1EPSS9.07%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Authentication Bypass Using an Alternate Path or Channel

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

CWE-288May 28, 2025
CVSS4.3v3.1EPSS0.216%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

CWE-528CWE-552May 28, 2025
CVSS4.0v3.1EPSS0.408%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Use of Password Hash Instead of Password for Authentication

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.

CWE-836May 28, 2025
CVSS4.3v3.1EPSS0.233%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Insecure Storage of Sensitive Information

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

CWE-613CWE-922May 28, 2025
CVSS4.0v3.1EPSS0.282%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smarsh telemessage Use of Hard-coded Credentials

The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.

CWE-798May 8, 2025
CVSS4.8v3.1EPSS0.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Hidden Functionality Vulnerability

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.

CWE-912May 8, 2025
CVSS1.9v3.1EPSS0.428%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX