CVE-2025-48925
Smarsh Telemessage ≤ 2025-05-05
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NSummary
CVE-2025-48925 is a medium-severity Use of Password Hash Instead of Password for Authentication (CWE-836) vulnerability in Smarsh Telemessage. Its CVSS base score is 4.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Pass the Hash (T1550.002); ranked at the 14th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-5 (Authenticator Management) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-16211
Vulnerability Data
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Requires proper identification and authentication of users, which structurally precludes accepting password hashes in place of passwords.
Authenticator management requires secure distribution, verification, and handling of passwords rather than allowing direct submission and comparison of hashes.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Proper authentication mechanisms require passwords (not pre-hashed values) to be supplied by the claimant and verified server-side.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Directly requires secure handling and protection of authentication credentials, preventing storage or comparison of password hashes as if they were passwords.
Mandates secure authentication mechanisms that preclude the flawed practice of treating password hashes as authenticators.
Requires proper cryptographic practices for protecting passwords, indirectly mitigating misuse of hashes in authentication.
Secure coding guidance can prevent this implementation error but does not address the control's broader intent.