Denial of Service Vulnerability in IBM Aspera High-Speed Transfer Products
CVE-2026-8180

7.5HIGH

What is CVE-2026-8180?

IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 to 4.4.7 Fix Pack 1 contain a vulnerability in the asperahttpd component that can lead to denial of service. An unauthenticated user can exploit this vulnerability to crash the asperahttpd service, potentially disrupting service availability. It is recommended to apply the necessary patches to mitigate this issue.

Affected Version(s)

Aspera High-Speed Transfer Endpoint 3.7.4 <= 4.4.7 Fix Pack 1

Aspera High-Speed Transfer Server 3.7.4 <= 4.4.7 Fix Pack 1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The vulnerabilities were reported to IBM by Yannik Marchand.
.