CVE-2023-27272: IBM Aspera Console weak password requirements
Published Apr 14, 2025
·Updated
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
Affected Software
4 affected components
IBM Aspera Console>=3.4.0<=3.4.4
All of the following
IBM Aspera Console>=3.4.0<3.4.5
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 14, 2025
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-27272?
CVE-2023-27272 has been rated as a medium severity vulnerability due to its potential impact on user password security.
2
How do I fix CVE-2023-27272?
To mitigate CVE-2023-27272, users should update their IBM Aspera Console to a version higher than 3.4.4 which addresses this issue.
3
What does CVE-2023-27272 affect?
CVE-2023-27272 affects IBM Aspera Console versions 3.4.0 through 3.4.4 by allowing password reuse for new user logins.
4
Who is affected by CVE-2023-27272?
Any user of IBM Aspera Console versions 3.4.0 to 3.4.4 is affected by CVE-2023-27272.
5
What happens if CVE-2023-27272 is exploited?
Exploitation of CVE-2023-27272 can lead to unauthorized access as users may unintentionally reuse passwords.