IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39899 | IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7181814 |
|
History
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Title | IBM Aspera Faspex information disclosure | |
| First Time appeared |
Ibm
Ibm aspera Faspex |
|
| Weaknesses | CWE-521 | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.10:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Faspex |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-02-12T16:47:02.895Z
Reserved: 2023-06-20T02:24:31.594Z
Link: CVE-2023-35907
Updated: 2025-02-12T16:46:55.225Z
Status : Received
Published: 2025-01-29T17:15:26.350
Modified: 2025-01-29T17:15:26.350
Link: CVE-2023-35907
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD