ZeroHour

CVE-2025-48928

KEVniche

Password Exposure via Core Dump Files in TeleMessage TM SGNL

CISA: TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

CVSS 3.1
4.0 medium
EPSS
<1%p45
Published
()
KEV added
AI analysis

CVE-2025-48928 is an information-disclosure flaw (CWE-528/CWE-552) in the TeleMessage TM SGNL service, marketed by Smarsh, as the service existed through 2025-05-05: its JSP application generates heap content roughly equivalent to a core dump, and any password previously sent to the service over HTTP remains in that dump. If heap or core dump files from the application become accessible to unauthorized parties, the attacker can read those retained passwords and other sensitive heap data. The flaw affects users and credentials whose traffic was processed by the TeleMessage TM SGNL service before May 5, 2025. It was exploited in the wild in May 2025, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-01; EPSS currently puts the 30-day exploitation probability at 0.6%.

What to do: If your organization uses TeleMessage TM SGNL, apply mitigations per Smarsh/TeleMessage vendor instructions or discontinue use of the service, following CISA BOD 22-01 cloud-service guidance as required by the KEV catalog entry. Rotate any credentials that were transmitted to the TeleMessage service over HTTP before 2025-05-05, since they may have been captured in heap dumps. No fixed release version is given in the available data, so confirm remediation status directly with the vendor.

Affected
smarsh telemessage (TeleMessage TM SGNL)TeleMessage service through 2025-05-05 (date-bounded; no specific version numbers provided)
Estimated exposure
niche~1k-10k users/credentials (niche enterprise/government secure-messaging cloud service); no published install base — TM SGNL is a niche managed secure-messaging gateway used by a limited set of enterprise and government customers rather than mass-market software, and no public install-base figures exist, so only a low-confidence order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

CISA Known Exploited Vulnerability
Affected
TeleMessage TM SGNL
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
smarsh
Products
telemessage
Weakness
CWE-528, CWE-552
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news