First published: Tue Mar 28 2023(Updated: )
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Cargo | <4.2.5 | |
IBM Aspera Connect | <4.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27284 has a high severity rating due to the potential for remote code execution via a buffer overflow.
To fix CVE-2023-27284, upgrade to versions of IBM Aspera Cargo and IBM Aspera Connect that are higher than 4.2.5.
CVE-2023-27284 affects IBM Aspera Cargo versions up to 4.2.5 and IBM Aspera Connect versions up to 4.2.5.
A buffer overflow in CVE-2023-27284 allows an attacker to exceed the buffer's storage capacity, leading to arbitrary code execution.
Any attacker with network access to the vulnerable versions of IBM Aspera Cargo or IBM Aspera Connect can potentially exploit CVE-2023-27284.