CVE-2025-2545
Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 2.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
05 mai 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Best Practical Solutions · Request TrackerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://docs.bestpractical.com/release-notes/rt/4.4.8https://docs.bestpractical.com/release-notes/rt/5.0.8https://lists.debian.org/debian-lts-announce/2025/05/msg00009.htmlhttps://www.incibe.es/en/incibe-cert/notices/aviso/cryptographic-algorithm-not-recommended-request-tracker-best-practical