SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-4436

Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service.

HIGH 7.5EPSS 3.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
3.09% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
ibm/aspera application platform on demand · ibm/aspera faspex on demand · ibm/aspera high-speed transfer endpoint · ibm/aspera high-speed transfer server · ibm/aspera high-speed transfer server for cloud pak for integration · ibm/aspera proxy server · ibm/aspera server on demand · ibm/aspera shares on demand · ibm/aspera streaming · ibm/aspera transfer cluster manager
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.