CVE-2023-35906: IBM Aspera Faspex security bypass
Published Aug 29, 2023
·Updated
IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.
Affected Software
5 affected components
IBM Aspera Faspex<=5.0.5 and prior
All of the following
Linux Linux Kernel
IBM Aspera Faspex<=5.0.5
IBM Aspera Faspex<=5.0.5
Linux Linux Kernel
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
via IBM·12:00 AM
Sep 5, 2023
CVE Published
via MITRE·12:52 AM
Data Sourced
via MITRE·12:52 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-35906.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Aspera could allow a remote attacker to bypass IP restrictions due to improper access controls.'
3
What is the affected software?
The affected software is IBM Aspera Faspex version 5.0.5 and prior.
4
What is the severity of CVE-2023-35906?
The severity of CVE-2023-35906 is high with a CVSS score of 7.5.
5
How can I fix the vulnerability?
To fix the vulnerability, upgrade IBM Aspera Faspex to a version higher than 5.0.5.