The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Telemessage | Smarsh | * | 2025-05-05 (including) |