← back
CVE-2025-48930lowobserved exploitationCWE-316

CVE-2025-48930

30Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 2.8epss 0.1%
from disclosure to weapon
Published on NVDMay 28
VulnCheckMay 28
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
yesVulnCheck
In short

TeleMessage stores sensitive information in unencrypted form in the computer's memory, where attackers who gain access to the system could potentially read it.

Technical detail

CWE-316 describes cleartext storage of sensitive data in memory. An adversary with local access or memory-reading capabilities can extract unencrypted sensitive information from the TeleMessage process memory. Mitigation requires encryption of sensitive data in-memory or secure memory handling practices.

Summary generated and translated by AI from the official description.
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected products
TeleMessage · service