nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-48930 CVE-2025-48930
LOW
smarsh telemessage Cleartext Storage of Sensitive Information in Memory
Record summary
CVE-2025-48930 has a selected CVSS score of 2.8 (low).
Description
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 28, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
TM SGNLBrowse TeleMessage / TM SGNL | VulnCheck | Version data not supplied | |
serviceBrowse TeleMessage / serviceDefault status: unknown | CVE List | Through 2025-05-05 | affected |
References
2wired.com
https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes