CVE-2025-2545: Best Practical Solutions Request Tracker
Low severity, CVSS 2.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Affected products
- Best Practical Solutions Request Tracker: before 5.0.8 (fixed in 5.0.8)
Published 2025-05-05. Last modified 2026-06-17.