SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-4434

Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service…

HIGH 7.5EPSS 2.60%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
2.60% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
ibm/aspera application platform on demand · ibm/aspera faspex on demand · ibm/aspera high-speed transfer endpoint · ibm/aspera high-speed transfer server · ibm/aspera high-speed transfer server for cloud pak for integration · ibm/aspera proxy server · ibm/aspera server on demand · ibm/aspera shares on demand · ibm/aspera streaming · ibm/aspera transfer cluster manager
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.