Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4157-1 request-tracker4 security update
Debian DSA Debian DSA DSA-5909-1 request-tracker5 security update
Debian DSA Debian DSA DSA-5911-1 request-tracker4 security update
EUVD EUVD EUVD-2025-13369 Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Ubuntu USN Ubuntu USN USN-7692-1 Request Tracker vulnerabilities
Fixes

Solution

The vulnerability has been fixed by the Best Practical Solutions, LLC team in version 5.0.8.


Workaround

No workaround given by the vendor.

History

Thu, 29 May 2025 11:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages. Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Title Cryptographic algorithm not recommended in Request Tracker by Best Practical Solutions Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME

Wed, 28 May 2025 18:30:00 +0000


Mon, 05 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 May 2025 11:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Title Cryptographic algorithm not recommended in Request Tracker by Best Practical Solutions
Weaknesses CWE-327
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-05-29T10:56:31.858Z

Reserved: 2025-03-20T09:12:46.915Z

Link: CVE-2025-2545

cve-icon Vulnrichment

Updated: 2025-05-28T17:57:12.306Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-05T12:15:16.170

Modified: 2025-05-29T11:15:20.477

Link: CVE-2025-2545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:08Z