CVE-2025-48928
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.55%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-528
- Published
- 2025-05-28
- Last modified
- 2026-02-26
Affected products
- TeleMessage service
Weakness type
Related vulnerabilities
- CVE-2024-10403 — SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav