← Vulnerability feed

Vulnerability record · CVE-2020-4433 · published 10 June 2020

CVE-2020-4433: Ibm aspera application platform on demand improper input validation vulnerability

Ibm · Aspera Application Platform On Demand

Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.

7.5 CVSS 3.1 High EPSS 5.1% · top 7.9% CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score, v2 9.3
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4433 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8175Ibm aspera high-speed transfer endpoint heap-based buffer overflow vulnerabilityIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…EPSS 0.94%9.1CVE-2026-7876Ibm aspera high-speed transfer server for cloud pak for integration improper authentication vulnerabilityIBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …EPSS 0.50%8.8CVE-2026-8179Ibm aspera high-speed transfer endpoint stack-based buffer overflow vulnerabilityIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…EPSS 0.61%7.5CVE-2026-8180Ibm aspera high-speed transfer endpoint null pointer dereference vulnerabilityIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…EPSS 0.48%7.5CVE-2020-4434Ibm aspera application platform on demand classic buffer overflow vulnerabilityCertain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an a…EPSS 2.6%7.5CVE-2020-4435Ibm aspera application platform on demand out-of-bounds write vulnerabilityCertain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with …EPSS 1.6%7.5CVE-2020-4436Ibm aspera application platform on demand classic buffer overflow vulnerabilityCertain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge o…EPSS 3.1%7.5CVE-2020-4432Ibm aspera application platform on demand command injection vulnerabilityCertain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2020-4433), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.