Aspera Console
Vendor:
First CVE: Dec 25, 2023 · Active for 2 years
18
Total CVEs
More Total CVEs than 93% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Aspera Console over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2023
2 years ago
Most Recent CVE
Mar 16, 2026
132 days ago
CVE Severity & Scoring
Aspera Console18 CVEs
61%
28%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.6%)
Network17 (94.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low9 (50.0%)
High2 (11.1%)
None7 (38.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13379HIGH IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m | Feb 5, 2026 | 8.6 | 28 | NO | NO |
CVE-2022-43842CRITICAL IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m | Feb 23, 2024 | 9.1 | 26 | NO | NO |
CVE-2023-27272HIGH IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system. | Apr 14, 2025 | 8.8 | 24 | NO | NO |
CVE-2021-38963HIGH IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a | Sep 25, 2024 | 8.0 | 24 | NO | NO |
CVE-2022-43851HIGH IBM Aspera Console 3.4.0 through 3.4.4
uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Apr 14, 2025 | 7.5 | 22 | NO | NO |
CVE-2022-43845HIGH IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploi | Sep 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-43852MEDIUM IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system. | Apr 14, 2025 | 5.3 | 19 | NO | NO |
CVE-2022-43850MEDIUM IBM Aspera Console 3.4.0 through 3.4.4
is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in | Apr 14, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-13460MEDIUM IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy. | Mar 16, 2026 | 5.3 | 18 | NO | NO |
CVE-2025-13925MEDIUM IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user. | Jan 20, 2026 | 4.9 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Aspera Console
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.7 | 1 | 4.9 | 0.3% | 0 | 0 |
| 3.4.2 | 5 | 5.8 | 0.3% | 0 | 0 |