CVE-2023-27279: IBM Aspera Faspex denial of service
Published Apr 18, 2024
·Updated
IBM Aspera Faspex 5 could allow a user to cause a denial of service due to missing API rate limiting.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.
— MITRE
Affected Software
2 affected components
IBM Aspera Faspex 5<=5.0.0 - 5.0.7
IBM Aspera Faspex>=5.0.0<=5.0.7
Event History
Apr 18, 2024
CVE Published
via IBM·12:00 AM
Apr 19, 2024
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-27279?
CVE-2023-27279 is classified as a denial of service vulnerability due to missing API rate limiting.
2
How do I fix CVE-2023-27279?
To mitigate CVE-2023-27279, upgrade IBM Aspera Faspex to version 5.0.8 or later.
3
Which versions of IBM Aspera Faspex are affected by CVE-2023-27279?
CVE-2023-27279 affects IBM Aspera Faspex versions 5.0.0 through 5.0.7.
4
What can exploit CVE-2023-27279?
CVE-2023-27279 can be exploited by an attacker sending numerous API requests, leading to service disruption.
5
Is authentication required to exploit CVE-2023-27279?
CVE-2023-27279 does not require authentication for exploitation, increasing its potential risk.