CVE-2025-36040

Severity
6.5MEDIUM
EPSS
0.0%
top 90.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 31

Description

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/aspera_faspex5.0.05.0.12.1
NVDibm/aspera_faspex5.0.05.0.12.1

🔴Vulnerability Details

2
GHSA
GHSA-v7j8-qgf8-rf5g: IBM Aspera Faspex 52025-07-31
CVEList
IBM Aspera Faspex session fixation2025-07-30
CVE-2025-36040 (MEDIUM CVSS 6.5) | IBM Aspera Faspex 5.0.0 through 5.0 | cvebase.io