S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-47986 Scanner

CVE-2022-47986 scanner - Remote Code Execution (RCE) vulnerability in IBM Aspera Faspex

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-47986
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Aspera Faspexby IBM
4.4.2 Patch Level 1 and earlier
Updated Aug 22, 2026View on NVD →
Detail

IBM Aspera Faspex is a file transfer software solution used by businesses to send and receive large files over the internet. It enables organizations to quickly and securely send large files and data sets of any size or format across different distances. Aspera Faspex provides a reliable and fast solution for businesses that require data transfer with high-speed and end-to-end security. With its user-friendly interface, Faspex also allows users to send and receive files from various platforms, including smartphones and tablets.

Recently, a serious vulnerability has been identified in IBM Aspera Faspex, known as CVE-2022-47986. This vulnerability is caused by a flaw in the software's YAML deserialization process, which can lead to remote code execution. Through the exploitation of CVE-2022-47986, attackers can remotely execute arbitrary code on the system and gain full control over the device. This could lead to a wide range of potential security breaches, including data breaches, theft of sensitive information, and other malicious activities.

If this vulnerability is exploited, it could lead to significant consequences for organizations. Attackers could potentially exploit this vulnerability to access, modify, or steal sensitive information. As a result, companies would be at risk of losing control over their confidential data, which can have severe consequences for their reputation, customer trust, and bottom line.

With s4e.io, businesses can easily and quickly learn about vulnerabilities in their digital assets. Our platform features advanced detection and tracking capabilities that enable businesses to stay up-to-date on potential threats and take corrective action before they can be exploited. Additionally, our team of experts provides support and guidance to help organizations protect their sensitive information and maintain their security posture. Contact us today to learn more about how we can help your business stay secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses can take several precautions, including:

  • Upgrade to the latest version of IBM Aspera Faspex (PL2) to remove the obsolete API call.
  • Implement strong access controls for the Faspex software, such as firewalls and access controls.
  • Use monitoring tools, including intrusion detection and prevention systems.
  • Conduct regular security audits to identify potential vulnerabilities and take corrective action before they are exploited.
  • Educate employees on best practices for secure file transfer and data handling.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-47986 scanner - Remote Code Execution (RCE) vulnerability in IBM Aspera Faspex | S4E