7.5
CVE-2020-4434
- EPSS 1.35%
- Published 10.06.2020 13:15:17
- Last modified 21.11.2024 05:32:44
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Aspera Application Platform On Demand Version <= 3.7.4
Ibm ≫ Aspera Faspex On Demand Version <= 3.7.4
Ibm ≫ Aspera High-speed Transfer Endpoint Version <= 3.9.3
Ibm ≫ Aspera High-speed Transfer Server Version <= 3.9.3
Ibm ≫ Aspera High-speed Transfer Server For Cloud Pak For Integration Version <= 3.9.10
Ibm ≫ Aspera Proxy Server Version <= 1.4.3
Ibm ≫ Aspera Server On Demand Version <= 3.7.4
Ibm ≫ Aspera Shares On Demand Version <= 3.7.4
Ibm ≫ Aspera Streaming Version <= 3.9.3
Ibm ≫ Aspera Transfer Cluster Manager Version <= 1.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.35% | 0.792 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
psirt@us.ibm.com | 7.5 | 1.6 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.