CVE-2025-47729

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telemessage:text_message_archiver:*:*:*:*:*:*:*:*

History

13 May 2025, 18:12

Type Values Removed Values Added
CWE NVD-CWE-Other
First Time Telemessage
Telemessage text Message Archiver
CPE cpe:2.3:a:telemessage:text_message_archiver:*:*:*:*:*:*:*:*
References () https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/ - () https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/ - Press/Media Coverage
References () https://news.ycombinator.com/item?id=43909220 - () https://news.ycombinator.com/item?id=43909220 - Press/Media Coverage
References () https://www.theregister.com/2025/05/05/telemessage_investigating/ - () https://www.theregister.com/2025/05/05/telemessage_investigating/ - Press/Media Coverage

13 May 2025, 01:00

Type Values Removed Values Added
Summary
  • (es) El backend de archivo de TeleMessage hasta el 5 de mayo de 2025 contiene copias de texto sin formato de los mensajes de los usuarios de la aplicación TM SGNL (también conocida como Archive Signal), lo que constituye una funcionalidad diferente a la descrita en la documentación de TeleMessage "Cifrado de extremo a extremo desde el teléfono móvil hasta el archivo corporativo", tal como se explotó en la naturaleza en mayo de 2025.

08 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-08 14:15

Updated : 2025-05-13 18:12


NVD link : CVE-2025-47729

Mitre link : CVE-2025-47729

CVE.ORG link : CVE-2025-47729


JSON object : View

Products Affected

telemessage

  • text_message_archiver
CWE
CWE-912

Hidden Functionality

NVD-CWE-Other