Aspera Proxy Server
Vendor:
First CVE: Jun 10, 2020 · Active for 6 years
5
Total CVEs
More Total CVEs than 77% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Aspera Proxy Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 10, 2020
6 years ago
Most Recent CVE
Jun 10, 2020
2,235 days ago
CVE Severity & Scoring
Aspera Proxy Server5 CVEs
100%
All CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High5 (100.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-4433HIGH Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of t | Jun 10, 2020 | 7.5 | 28 | NO | NO |
CVE-2020-4432HIGH Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute comma | Jun 10, 2020 | 7.5 | 26 | NO | NO |
CVE-2020-4436HIGH Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitra | Jun 10, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-4435HIGH Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the syste | Jun 10, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-4434HIGH Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge | Jun 10, 2020 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Aspera Proxy Server
Top CWEs
Versions
No cataloged versions.