Description
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
Published: 2026-03-13
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

IBM Aspera Console versions 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow, as detailed by the vendor’s description. This flaw permits the attacker to interrupt normal operation of the console, thereby compromising availability for users interacting with the service. The weakness is associated with CWE-841, indicating a defect in how system behavior is enforced or logged. The impact is localized to systems running the affected console and does not directly expose data or allow remote code execution.

Affected Systems

Affected products include IBM Aspera Console for Windows and Linux platforms. All releases from 3.3.0 up to and including 3.4.8 are impacted, encompassing both the 3.3.x and 3.4.x series. No other vendor products are listed in the CNA data, and the CPE entries confirm the scope is limited to the Aspera Console application itself.

Risk and Exploitability

The CVSS score of 2.7 places this vulnerability in the low severity range, and the EPSS score indicates a probability of exploitation of less than 1%. It is not listed in the CISA KEV catalog, suggesting no large-scale exploitation has been reported. The attack vector is likely local or requires privileged access, as the vulnerability exploits improper enforcement of workflow for privileged users. Nevertheless, any insider or compromised administrative account could use this flaw to interrupt service availability, making it important for administrators to apply the recommended patch promptly.

Generated by OpenCVE AI on March 17, 2026 at 17:32 UTC.

Remediation

Vendor Solution

Remediation/Fixes It is strongly recommended that customers upgrade to the latest version of IBM Aspera Console: Product(s) Fixing VRM Platform Link to Fix IBM Aspera Console 3.4.9 Windows Link IBM Aspera Console 3.4.9 Linux Link


OpenCVE Recommended Actions

  • Apply the vendor’s remediation by upgrading IBM Aspera Console to version 3.4.9 or later, as recommended in the CNA solution.

Generated by OpenCVE AI on March 17, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:aspera_console:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows

Mon, 16 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
Title IBM Aspera Console Denial of Service
First Time appeared Ibm
Ibm aspera Console
Weaknesses CWE-841
CPEs cpe:2.3:a:ibm:aspera_console:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_console:3.4.8:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Console
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ibm Aspera Console
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-16T13:51:49.820Z

Reserved: 2025-11-19T20:57:57.020Z

Link: CVE-2025-13459

cve-icon Vulnrichment

Updated: 2026-03-16T13:51:46.260Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-16T14:17:54.710

Modified: 2026-03-17T15:49:45.937

Link: CVE-2025-13459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T13:40:04Z

Weaknesses