CVE-2023-37412: IBM Aspera Faspex improper access control
Published Jan 28, 2025
·Updated
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
Other sources
IBM Aspera Faspex could allow a privileged user to make system changes without proper access controls.
— IBM
Affected Software
2 affected components
IBM Aspera Faspex 5<=5.0.0 - 5.0.10
IBM Aspera Faspex>=5.0.0<=5.0.10
Event History
Jan 28, 2025
CVE Published
via IBM·12:00 AM
Jan 29, 2025
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37412?
CVE-2023-37412 has a high severity level due to the potential for privileged users to make unauthorized system changes.
2
How do I fix CVE-2023-37412?
To fix CVE-2023-37412, upgrade IBM Aspera Faspex to a version higher than 5.0.10.
3
What are the impacts of CVE-2023-37412?
CVE-2023-37412 may allow a privileged user to compromise the integrity of the system and perform unauthorized actions.
4
Who is affected by CVE-2023-37412?
CVE-2023-37412 affects users of IBM Aspera Faspex versions 5.0.0 through 5.0.10.
5
Is CVE-2023-37412 being actively exploited?
As of now, there is no public information indicating that CVE-2023-37412 is being actively exploited in the wild.