
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was identified in Best Practical Solutions, LLC's Request Tracker versions 4.4.x through 4.4.7 and 5.0.x through 5.0.7, tracked as CVE-2025-2545, discovered in March 2025. The vulnerability involves the use of the Triple DES (3DES) cryptographic algorithm within SMIME code for encrypting S/MIME emails (Wiz, INCIBE).
The vulnerability specifically impacts the SMIME email encryption functionality in Request Tracker, where the system uses the default OpenSSL cipher, 3DES (des3), for encrypting SMIME email. The vulnerability has been assigned a CVSS v4.0 base score of 2.3 with the vector AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N and is categorized as CWE-327 (INCIBE, Wiz).
The use of the outdated 3DES cipher for SMIME email encryption could potentially compromise the confidentiality of encrypted email communications within the Request Tracker system. The vulnerability has been classified as low severity due to its limited impact scope (Wiz).
The vulnerability has been fixed in Request Tracker versions 4.4.6+dfsg-1.1+deb12u2 and 5.0.3+dfsg-3~deb12u3 for the Debian bookworm release. The fixes are implemented through commits a5042a30aaa0fcf4255d0a06ee2659d302742fc3 (rt-4.4.8) and a63c2534b3227de5be820cf4c1e4088dc0203020 (rt-5.0.8). Users are advised to upgrade to these patched versions (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."