CVE-2023-27285: IBM Aspera Cargo

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248625.

Affected products

  • IBM Aspera Cargo: before 4.2.6 (fixed in 4.2.6)
  • IBM Aspera Connect: before 4.2.6 (fixed in 4.2.6)

Published 2023-06-05. Last modified 2026-06-17.