Описание
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
Ссылки
- Press/Media Coverage
Уязвимые конфигурации
Конфигурация 1Версия до 2025-05-05 (включая)
cpe:2.3:a:smarsh:telemessage:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00044
Низкий
4.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-836
Связанные уязвимости
CVSS3: 4.3
github
9 месяцев назад
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential, as exploited in the wild in May 2025.
EPSS
Процентиль: 13%
0.00044
Низкий
4.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-836