CVE-2025-48929
28.05.2025, 17:15
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.Enginsight
| Vendor | Product | Version |
|---|---|---|
| smarsh | telemessage | 𝑥 ≤ 2025-05-05 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-922 - Insecure Storage of Sensitive InformationThe software stores sensitive information without properly limiting read or write access by unauthorized actors.
- CWE-613 - Insufficient Session ExpirationAccording to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."