CVE-2025-48928MEDIUM 4.0CISA KEVEPSS p28.3%
CVE-2025-48928TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability
TeleMessage / TM SGNL
Description
TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.
Scoring
| CVSS 3.1 | 4.0 (MEDIUM) |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.37% probability of exploitation · percentile 28.3% · 2026-06-19T12:03:05Z |
| Published | 2025-05-28 |
| Last modified | 2025-11-05 |
CISA KEV entry
Added to KEV: 2025-07-01
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Core Dump File to an Unauthorized Control Spherecwe-528 | 0% | live |
| Weakness | Files or Directories Accessible to External Partiescwe-552 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerabilitykev-cve-2025-48928 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.