Deserialization of Untrusted Data in IBM Aspera Faspex for Windows and IBM Aspera Faspex for Linux - CVE-2022-47986
Published: February 9, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized YAML data. A remote attacker can send a specially crafted request to an obsolete API endpoint and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Aspera Faspex for Linux
How to mitigate CVE-2022-47986
IBM Aspera Faspex for Linux - update to 4.4.2 PL2
Links to Public Exploits and PoC-codes
- Exploit #10730 - IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE) (October 25, 2024)
- Exploit #8902 - CVE-2022-47986 (CVE-2022-47986: Python, Ruby, NMAP and Metasploit modules to exploit the vulnerability.) (March 10, 2023)
- Exploit #8819 - CVE-2022-47986 (Aspera Faspex Pre Auth RCE) (February 9, 2023)
- Exploit #8818 - Weaponized-CVEs (A collection of CVE's that are weaponized to exploit whatever PoC it is exploiting. Such as automatically dropping beacons and shells. ) (February 9, 2023)