Skip to content
COOEY

EXPOSURES › CVE-2025-47729

CVE-2025-47729

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-05-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-47729 ↗
⌖ EXPLOITED IN THE WILD SHAME 88/100 exploited-in-wilddata-breachunpatched

TeleMessage's TM SGNL stored user messages in cleartext, creating a significant data exposure risk and actively exploited in the wild.

TM SGNL's archiving backend stored messages in cleartext, exposing sensitive user data. This failure represents a severe compliance risk for DIB organizations using the product, potentially violating CMMC and NIST 800-171 requirements. Organizations should immediately assess their use of TM SGNL and implement mitigating controls or consider alternative solutions.

Shame score — Storing sensitive user data in cleartext is a fundamental security failure, especially given active exploitation, demonstrating significant negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.