VulnerabilityModified
CVE-2020-4436
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service.
HIGH 7.5EPSS 3.09%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.09% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- ibm/aspera application platform on demand · ibm/aspera faspex on demand · ibm/aspera high-speed transfer endpoint · ibm/aspera high-speed transfer server · ibm/aspera high-speed transfer server for cloud pak for integration · ibm/aspera proxy server · ibm/aspera server on demand · ibm/aspera shares on demand · ibm/aspera streaming · ibm/aspera transfer cluster manager
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/180902VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6221324Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/180902VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6221324Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.