CVE-2025-47729
LOW(1.9)KEV
TeleMessage TM SGNL Hidden Functionality Vulnerability
Description
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:NOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| telemessage | text message archiver | <= 2025-05-05 |
Multiple CVSS Assessments
Source: [email protected](Secondary)
1.9
LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Source: [email protected](Primary)
4.9
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
References
- https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/(Press/Media Coverage)
- https://news.ycombinator.com/item?id=43909220(Press/Media Coverage)
- https://www.theregister.com/2025/05/05/telemessage_investigating/(Press/Media Coverage)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47729(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.