CVE-2023-22862: IBM Aspera Cargo

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected products

  • IBM Aspera Cargo: before 4.2.6 (fixed in 4.2.6)
  • IBM Aspera Connect: before 4.2.6 (fixed in 4.2.6)

Published 2023-06-05. Last modified 2026-06-17.