CVE-2025-2545
LOWBest Practical Solutions, LLC's Request Tracker <5.0.8 - Info Discl...
Title source: llmDescription
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
References (4)
Scores
CVSS v4
2.3
EPSS
0.0015
EPSS Percentile
35.0%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-327
Status
published
Products (1)
Best Practical Solutions/Request Tracker
< 5.0.8
Published
May 05, 2025
Tracked Since
Feb 18, 2026