ZeroHour

CVE-2025-47729

KEVniche

Hidden cleartext message storage in TeleMessage TM SGNL archiving backend

CISA: TeleMessage TM SGNL Hidden Functionality Vulnerability

CVSS 3.1
4.9 medium
EPSS
<1%p36
Published
()
KEV added
AI analysis

TeleMessage's archiving backend (through 2025-05-05) silently retains cleartext copies of messages sent by users of the TM SGNL (Archive Signal) app, despite TeleMessage documentation advertising end-to-end encryption from the mobile phone through to the corporate archive. This stems from hidden backend functionality (CWE-912) rather than a remotely triggerable code flaw, and it was exploited in the wild in May 2025. Anyone who can reach those backend message stores, such as an attacker who compromises TeleMessage's infrastructure or the customer-facing archive, gains access to plaintext copies of users' messages, a high confidentiality impact reflected in the CVSS 4.9 score (high privileges required, no integrity or availability impact). Organizations and personnel who used TM SGNL through 2025-05-05 for compliance archiving are affected, including regulated enterprises and government users of the service. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2025-05-12 with no public proof-of-concept known, and EPSS estimates a 0.4% chance of exploitation in the next 30 days.

What to do: Apply mitigations per TeleMessage vendor instructions and follow applicable CISA BOD 22-01 guidance for cloud services, discontinuing use of TM SGNL if mitigations are unavailable. Treat messages archived through 2025-05-05 as potentially stored in cleartext and review backend/archive access controls and logs for signs of unauthorized access. Federal agencies must remediate per the KEV catalog deadline (added 2025-05-12).

Affected
TeleMessage TM SGNL (Archive Signal) app with TeleMessage archiving backend (text message archiver)archiving backend through 2025-05-05
Estimated exposure
nicheunknown; plausibly on the order of thousands to tens of thousands of users across TeleMessage's enterprise and government compliance-archiving customer base — TM SGNL is a niche compliance-archiving add-on sold to regulated enterprises and a small set of government agencies rather than a mass-market product, and no public install, device, or user counts are available in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.

CISA Known Exploited Vulnerability
Affected
TeleMessage TM SGNL
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
telemessage
Products
text message archiver
Weakness
CWE-912
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news