We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2545

Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME



Description

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

Reserved 2025-03-20 | Published 2025-05-05 | Updated 2025-05-29 | Assigner INCIBE


LOW: 2.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-327 Use of a Broken or Risky Cryptographic Algorithm

Product status

Default status
unaffected

Any version before 5.0.8
affected

Credits

Ángel González Berdasco finder

References

www.incibe.es/...-recommended-request-tracker-best-practical

cve.org (CVE-2025-2545)

nvd.nist.gov (CVE-2025-2545)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2545

Support options

Helpdesk Chat, Email, Knowledgebase