Fiche vulnérabilité
CVE-2023-35907 : faille critique ibm aspera faspex (CVSS 9.8)
Description
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 29 janv. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ibm aspera faspex