PT-2025-23114 · Unknown · Telemessage
Published
2025-05-28
·
Updated
2025-05-28
·
CVE-2025-48931
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TeleMessage service through 2025-05-05
Description
The issue concerns the use of MD5 for password hashing, which allows for various attack possibilities, including the use of rainbow tables, with low computational effort.
Recommendations
For versions through 2025-05-05, consider updating the password hashing mechanism to a more secure algorithm to mitigate the risk of attacks using rainbow tables or other methods exploiting the weakness of MD5.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telemessage