Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 2, 2025

CVE-2025-47729

High
EPSS 4.1%CISA KEV
TeleMessage/TM SGNL

Description

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.

EPSS — Exploit Probability

4.1%

Higher than 88.5% of all CVEs

Required Action

Apply mitigations per vendor instructions. Absent mitigating instructions from the vendor, discontinue use of the product. ; https://nvd.nist.gov/vuln/detail/CVE-2025-47729

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
4.1%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 12, 2025

Added to KEV

May 12, 2025

Remediation Due

Jun 2, 2025

Affected Product

TeleMessage

TM SGNL

View all TeleMessage CVEs