CVE-2025-36171
CVE-2025-36171 is a medium-severity vulnerability in Ibm Aspera Faspex with a CVSS 3.x base score of 4.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-770.
Key facts
- Severity: Medium (CVSS 3.x base score 4.9)
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-33345
- Weakness: CWE-770
- Affected product: Ibm Aspera Faspex
- Published:
- Last modified:
Description
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
Frequently asked questions
- What is CVE-2025-36171?
- IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
- How severe is CVE-2025-36171?
- CVE-2025-36171 has a CVSS 3.x base score of 4.9, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2025-36171 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-36171?
- CVE-2025-36171 affects Ibm Aspera Faspex. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-36171?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-36171 have an EU (EUVD) identifier?
- Yes. CVE-2025-36171 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-33345.
- When was CVE-2025-36171 published?
- CVE-2025-36171 was published on 2025-10-09 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*:*
More vulnerabilities in Ibm Aspera Faspex
- CVE-2023-27874 — Critical (CVSS 9.9): IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A…
- CVE-2022-47986 — Critical (CVSS 9.8): IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the…
- CVE-2026-14959 — Critical (CVSS 9.1): IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to…
- CVE-2026-14958 — Critical (CVSS 9.1): IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to…
- CVE-2026-14996 — High (CVSS 8.2): IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
- CVE-2023-37400 — High (CVSS 7.8): IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential…
All CVEs affecting Ibm Aspera Faspex →
Other CWE-770 (Allocation of Resources Without Limits or Throttling) vulnerabilities
- CVE-2026-63299 — Critical (CVSS 9.9): An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume…
- CVE-2026-74878 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared…
- CVE-2026-31283 — Critical (CVSS 9.8): In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email…
- CVE-2020-37067 — Critical (CVSS 9.8): Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers…
- CVE-2021-47875 — Critical (CVSS 9.8): GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the…
- CVE-2025-11832 — Critical (CVSS 9.8): Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access…
Browse all CWE-770 (Allocation of Resources Without Limits or Throttling) vulnerabilities →