CVE-2023-37398: IBM Aspera Faspex information disclosure
IBM Aspera does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37398?
CVE-2023-37398 is considered a medium severity vulnerability due to the lack of strong password requirements.
How do I fix CVE-2023-37398?
To fix CVE-2023-37398, implement a strong password policy in your IBM Aspera Faspex settings.
What versions of IBM Aspera are affected by CVE-2023-37398?
CVE-2023-37398 affects IBM Aspera Faspex versions 5.0.0 through 5.0.10.
What are the risks associated with CVE-2023-37398?
The main risk associated with CVE-2023-37398 is that weak passwords can lead to account compromise by attackers.
Is there a patch available for CVE-2023-37398?
There is no specific patch for CVE-2023-37398, but upgrading to a version with improved password policies is recommended.