Lucene search

K
cvelistIbmCVELIST:CVE-2023-27286
HistoryMar 28, 2023 - 8:07 p.m.

CVE-2023-27286 IBM Aspera code execution

2023-03-2820:07:54
CWE-119
ibm
www.cve.org
4
ibm
aspera
buffer overflow
cargo
connect
vulnerability
code execution

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

64.9%

IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Aspera",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "4.2.5"
      }
    ]
  }
]

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

64.9%

Related for CVELIST:CVE-2023-27286