Account Compromise Risk in IBM Aspera Faspex by Weak Password Policy
CVE-2023-37398

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 January 2025

Summary

The IBM Aspera Faspex application versions 5.0.0 through 5.0.10 are susceptible to a vulnerability that allows users to set weak passwords by default. This lack of enforced password strength can lead to increased risk of unauthorized access, as attackers may exploit this weakness to compromise user accounts. Organizations using these versions should review their password policies and consider implementing stronger authentication measures to mitigate potential risks.

Affected Version(s)

Aspera Faspex 5.0.0 <= 5.0.10

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.