CVE-2025-48929
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.
Affected (1)
Products: Smarsh: Telemessage
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2025-05-05 |
Related CWEs
CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CWE-922
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
References (1)
Source: cve@mitre.org
Press/Media Coverage
Timeline
No history available yet.