Privilege Escalation Vulnerability in IBM Aspera Faspex
CVE-2023-37400

7.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
19 April 2024

Summary

IBM Aspera Faspex versions 5.0.0 through 5.0.7 are susceptible to a vulnerability that enables local users to escalate their privileges. This issue arises from the insecure storage of credentials, which could be exploited by malicious parties to gain elevated access within the system. Organizations utilizing affected versions should take immediate steps to review their security practices and implement necessary patches to mitigate potential risks associated with unauthorized access.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.