Aspera Console

Vendor:

First CVE: Dec 25, 2023 · Active for 2 years

18
Total CVEs
More Total CVEs than 93% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Aspera Console over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2023
2 years ago
Most Recent CVE
Mar 16, 2026
132 days ago

CVE Severity & Scoring

Aspera Console18 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local1 (5.6%)
Network17 (94.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low9 (50.0%)
High2 (11.1%)
None7 (38.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m
Feb 5, 20268.628NONO
IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m
Feb 23, 20249.126NONO
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
Apr 14, 20258.824NONO
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a
Sep 25, 20248.024NONO
IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Apr 14, 20257.522NONO
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploi
Sep 25, 20247.522NONO
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.
Apr 14, 20255.319NONO
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in
Apr 14, 20255.419NONO
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
Mar 16, 20265.318NONO
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
Jan 20, 20264.918NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Aspera Console

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.4.714.90.3%00
3.4.255.80.3%00