Lucene search

K
ibmIBM2462F60D0D584832DA6F1BE3EF2B184ECC33BF40E970645CC3A90D2F3A11B9D9
HistoryFeb 02, 2023 - 4:40 p.m.

Security Bulletin: IBM Aspera faspio Gateway affected by OpenSSL vulnerabilities (CVE-2022-3602, CVE-2022-3786)

2023-02-0216:40:59
www.ibm.com
23
ibm aspera gateway
openssl
buffer overflow
cve-2022-3602
cve-2022-3786
denial of service
vulnerability
linux
mac osx
windows

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.102

Percentile

95.0%

Summary

IBM Aspera faspio Gateway 1.3.1 has addressed the following vulnerabilities.

Vulnerability Details

CVEID:CVE-2022-3602
**DESCRIPTION:**OpenSSL is vulnerable to a stack-based buffer overflow, caused by improper bounds checking during X.509 certificate verification. By using a specially-crafted email address, a remote attacker could overflow a buffer and execute arbitrary code or cause the application to crash.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/239161 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2022-3786
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a stack based buffer overflow during X.509 certificate verification. By using a specially-crafted email address in a certificate, a remote attacker could exploit this vulnerability to cause a TLS client to crash, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/239165 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM Aspera faspio Gateway 1.2.1 and earlier

Remediation/Fixes

The recommended solution is to apply the fix as soon as possible:

Product(s) Fixing VRM Platform(s) Link to Fix
IBM Aspera faspio Gateway 1.3.1 Linux click here
IBM Aspera faspio Gateway

1.3.1

| Linux PPC| click here
IBM Aspera faspio Gateway|

1.3.1

| Linux zSeries| click here
IBM Aspera faspio Gateway|

1.3.1

| Mac OSX| click here
IBM Aspera faspio Gateway|

1.3.1

| Windows| click here

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmaspera_faspexMatch4.4.0
OR
ibmaspera_faspexMatch3.4.0
OR
ibmaspera_faspexMatch3.2.0
VendorProductVersionCPE
ibmaspera_faspex4.4.0cpe:2.3:a:ibm:aspera_faspex:4.4.0:*:*:*:*:*:*:*
ibmaspera_faspex3.4.0cpe:2.3:a:ibm:aspera_faspex:3.4.0:*:*:*:*:*:*:*
ibmaspera_faspex3.2.0cpe:2.3:a:ibm:aspera_faspex:3.2.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.102

Percentile

95.0%