Showing 2 vulnerabilities on this page for archiving backend

Signals CISA KEV Ransomware Nuclei
TeleMessage vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

smarsh telemessage Use of Hard-coded Credentials

The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.

CWE-798May 8, 2025
CVSS4.8v3.1EPSS0.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TeleMessage TM SGNL Hidden Functionality Vulnerability

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.

CWE-912May 8, 2025
CVSS1.9v3.1EPSS0.428%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX