Description
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.
Published: 2026-05-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 FP1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 FP1 are vulnerable to a denial‑of‑service flaw in the asperahttpd component. This flaw can be triggered by an unauthenticated user, causing the service to crash and leading to an interruption of all data‑transfer operations. The issue is identified as a null pointer dereference, as indicated by CWE‑476, which results in abnormal termination of the process. No specific exploit details are publicly known, and the attack appears to require simple network-level access to the asperahttpd service.

Affected Systems

IBM Aspera High-Speed Transfer Endpoint versions 3.7.4 through 4.4.7 FP1 and IBM Aspera High-Speed Transfer Server versions 3.7.4 through 4.4.7 FP1 are affected. Versions beyond 4.4.7 FP1, such as the Fix Pack 2 releases, are not impacted by this vulnerability. Both products are identified in the CPE namespace for the provided versions.

Risk and Exploitability

The CVSS score of 7.5 classifies this as a moderate‑severity vulnerability, while the EPSS score is currently not available, indicating no publicly known exploitation rate. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely without requiring authentication by simply sending a request to asperahttpd that triggers the null pointer dereference, resulting in a denial of service for all users.

Generated by OpenCVE AI on May 27, 2026 at 21:21 UTC.

Remediation

Vendor Solution

Product(s)VRMFRemediation/First FixIBM Aspera High-Speed Transfer Server4.4.7 Fix Pack 2Link to latest release (4.4.7 FP 2)IBM Aspera High-Speed Transfer Endpoint4.4.7 Fix Pack 2Link to latest release (4.4.7 FP 2)


OpenCVE Recommended Actions

  • Apply IBM Aspera High-Speed Transfer Server 4.4.7 Fix Pack 2 to resolve the asperahttpd denial‑of‑service flaw
  • Apply IBM Aspera High-Speed Transfer Endpoint 4.4.7 Fix Pack 2 to mitigate the vulnerability
  • Restrict external access to the asperahttpd service by configuring firewall rules or network segmentation to limit unauthenticated connections until the patch is applied

Generated by OpenCVE AI on May 27, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:4.4.7:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:4.4.7:fixpack1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high-speed_transfer_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high-speed_transfer_server:4.4.7:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high-speed_transfer_server:4.4.7:fixpack1:*:*:*:*:*:*

Thu, 28 May 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aspera High-speed Transfer Endpoint
Ibm aspera High-speed Transfer Server
Vendors & Products Ibm aspera High-speed Transfer Endpoint
Ibm aspera High-speed Transfer Server

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.
Title Multiple vulnerabilities in Aspera applications.
First Time appeared Ibm
Ibm aspera High Speed Transfer Endpoint
Ibm aspera High Speed Transfer Server
Weaknesses CWE-476
CPEs cpe:2.3:a:ibm:aspera_high_speed_transfer_endpoint:3.7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high_speed_transfer_endpoint:4.4.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high_speed_transfer_server:3.7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_high_speed_transfer_server:4.4.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera High Speed Transfer Endpoint
Ibm aspera High Speed Transfer Server
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Aspera High-speed Transfer Endpoint Aspera High-speed Transfer Server Aspera High Speed Transfer Endpoint Aspera High Speed Transfer Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-05-28T19:21:26.833Z

Reserved: 2026-05-08T16:17:39.551Z

Link: CVE-2026-8180

cve-icon Vulnrichment

Updated: 2026-05-28T19:21:19.886Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T14:17:38.170

Modified: 2026-06-05T18:56:59.087

Link: CVE-2026-8180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T04:30:06Z

Weaknesses