VulnerabilityModified
CVE-2023-22870
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques.
MEDIUM 5.9EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- ibm/aspera faspex
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/244121VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7029681Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/244121VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7029681Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.