CVE-2025-36171: IBM Aspera Faspex denial of service
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
Other sources
IBM Aspera Faspex could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36171?
CVE-2025-36171 has a severity rating that indicates the potential for denial of service due to excessive resource consumption.
How do I fix CVE-2025-36171?
To fix CVE-2025-36171, it is recommended to update IBM Aspera Faspex to the latest version beyond 5.0.13.1.
Who is affected by CVE-2025-36171?
CVE-2025-36171 affects users of IBM Aspera Faspex versions 5.0.0 to 5.0.13.1.
What kind of attack does CVE-2025-36171 facilitate?
CVE-2025-36171 facilitates denial of service attacks through improperly validated API input.
Which API aspects are vulnerable in CVE-2025-36171?
CVE-2025-36171 is vulnerable due to improper validation of input, leading to excessive resource consumption.