CVE-2025-48928KEV · OVERDUECWE-528

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

Medium · published May 28, 2025

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 4.0. It is confirmed in active exploitation. It sits in the 44.2th percentile for exploit probability.

412
days past CISA
deadline
CVSS v3.1
4.0
EPSS
1%
Percentile
44.2
In the wild
Confirmed
What it is

⚠️ A hidden gem for attackers! The TeleMessage service could inadvertently leak passwords in a memory dump, like a forgotten note left on a public table. 🚨 Think of it like a diner accidentally leaving its order slip on the counter—anyone can see what was just done, including sensitive information. In this case, the heap content of the JSP application acts as that unattended slip, revealing previously sent passwords over HTTP. This vulnerability may allow malicious actors to scoop up sensitive user passwords directly from memory dumps, potentially leading to account takeovers or unauthorized access. The consequences could be frustratingly real—imagine someone walking away with your secret sauce recipe!

Put simply

Think of it like a diner accidentally leaving its order slip on the counter—anyone can see what was just done, including sensitive information. In this case, the heap content of the JSP application acts as that unattended slip, revealing previously sent passwords over HTTP. The vulnerability arises from the JSP application’s handling of heap content, where sensitive information, such as passwords sent over HTTP, can inadvertently be included in a memory dump, exposing it to unauthorized access.

What to do

This vulnerability may allow malicious actors to scoop up sensitive user passwords directly from memory dumps, potentially leading to account takeovers or unauthorized access. The consequences could be frustratingly real—imagine someone walking away with your secret sauce recipe! To mitigate this issue, ensure you migrate to a secure protocol (like HTTPS) for password transmission. Additionally, monitor for any signs of exploitation and consider updating your application's memory management practices to prevent sensitive data leakage. You’ve got this! With the right steps, you can safeguard your users’ data and keep those secrets safe! 🛡️

The record
Technical detail
CVSS v3.1
4.0 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00553 · 44.2th percentile
Weakness
CWE-528 · Exposure of Core Dump File to an Unauthorized Control Sphere
Published
2025-05-28T00:00Z
KEV added
2025-07-01 · due 2025-07-22
EPSS history
Timeline
  • 01 JUL 00:00Z
    Added to CISA KEV — remediate by Jul 22
    kev
  • 28 MAY 00:00Z
    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password…
    cvelistv5