First published: Mon Apr 14 2025(Updated: )
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Console | >=3.4.0<=3.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27272 has been rated as a medium severity vulnerability due to its potential impact on user password security.
To mitigate CVE-2023-27272, users should update their IBM Aspera Console to a version higher than 3.4.4 which addresses this issue.
CVE-2023-27272 affects IBM Aspera Console versions 3.4.0 through 3.4.4 by allowing password reuse for new user logins.
Any user of IBM Aspera Console versions 3.4.0 to 3.4.4 is affected by CVE-2023-27272.
Exploitation of CVE-2023-27272 can lead to unauthorized access as users may unintentionally reuse passwords.