CVE-2023-27284: IBM Aspera Cargo

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.

Affected products

  • IBM Aspera Cargo: before 4.2.5 (fixed in 4.2.5)
  • IBM Aspera Connect: before 4.2.5 (fixed in 4.2.5)

Published 2023-04-02. Last modified 2026-06-17.