CVE-2025-47729

LOW KEV

TeleMessage <2025-05-05 - Info Disclosure

Title source: llm

Description

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.

Scores

CVSS v3 1.9
EPSS 0.0415
EPSS Percentile 88.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

Exploitation Intel

CISA KEV 2025-05-12
VulnCheck KEV 2025-05-08
ENISA EUVD EUVD-2025-14003

Classification

CWE
CWE-912
Status published

Affected Products (1)

telemessage/text_message_archiver < 2025-05-05

Timeline

Published May 08, 2025
KEV Added May 12, 2025
Tracked Since Feb 18, 2026