Aspera Orchestrator 4.0.1 Vulnerability Allows Remote Execution of Arbitrary Commands
CVE-2023-37407

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
3 May 2024

Summary

IBM Aspera Orchestrator version 4.0.1 is susceptible to a vulnerability that enables remote authenticated attackers to send specially crafted requests, which could lead to the execution of arbitrary commands on the affected system. This exploitation potential presents significant risks for the integrity and confidentiality of the system and its data. Organizations utilizing this version of Aspera Orchestrator should prioritize applying available patches and implement monitoring procedures to safeguard against potential attacks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.