PT-2025-23113 · Unknown · Telemessage
Micah Lee
·
Published
2025-05-28
·
Updated
2025-10-22
·
CVE-2025-48930
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TeleMessage service through 2025-05-05
Description
The issue concerns the storage of certain cleartext information in memory by the TeleMessage service. This information may be accessible to an adversary through various means. There have been real-world incidents where this issue was exploited, specifically in May 2025.
Recommendations
For the TeleMessage service through 2025-05-05, consider implementing memory encryption or secure data storage practices to protect sensitive information. As a temporary workaround, restrict access to sensitive data and monitor for any suspicious activity. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telemessage