CVE-2021-38963
CVSS 3.1 Score 8 of 10 (high)
Details
Published Sep 25, 2024
Updated: Sep 30, 2024
CWE ID 1236
Summary
CVE-2021-38963 is a vulnerability affecting IBM Aspera Console versions 3.4.0 through 3.4.4. This issue enables a remote, authenticated attacker to execute arbitrary code on the system. The exploit is facilitated by a CSV injection vulnerability, which can be triggered by persuading a victim to open a maliciously crafted file. This vulnerability poses a significant risk, as it allows an attacker to gain unauthorized access and potentially control of the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation