Vulnerability record · CVE-2022-47986 · published 17 February 2023
CVE-2022-47986: IBM Aspera Faspex YAML Deserialization Remote Code Execution
Ibm · Aspera Faspex
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier contain a YAML deserialization flaw (CWE-502) reachable through an obsolete API call. A remote, unauthenticated attacker can send a crafted request to execute arbitrary code on the server. The vulnerable API call was removed in Faspex 4.4.2 PL2, so the fix is a version upgrade.
Description
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, KEV listing, documented ransomware use, and near-maximum EPSS probability.
What it is
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier contain a YAML deserialization flaw (CWE-502) reachable through an obsolete API call. A remote, unauthenticated attacker can send a crafted request to execute arbitrary code on the server. The vulnerable API call was removed in Faspex 4.4.2 PL2, so the fix is a version upgrade.
Impact
Successful exploitation gives the attacker arbitrary code execution on the Faspex server, typically with the privileges of the Faspex service. That enables data theft, lateral movement into the file-transfer environment, and full host compromise.
Attack surface
Reachable over the network via the Faspex HTTP(S) interface using the obsolete API endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
CISA added it to KEV on 2023-02-21 with a 2023-03-14 remediation due date and flags known ransomware campaign use; EPSS is 0.99968 (99.976th percentile), and public exploit material is referenced via Packet Storm.
What to do
- Upgrade IBM Aspera Faspex to 4.4.2 Patch Level 2 or later, which removes the obsolete API call.
- If immediate upgrade is not possible, block or restrict network access to the Faspex web/API interface to trusted sources only.
- Treat any internet-exposed Faspex instance as compromised until triaged, given KEV listing and ransomware use.
- Monitor IBM's advisory page (node/6952319) for updated guidance and interim fixes.
Detection
- Inspect Faspex HTTP access logs for requests to obsolete or unexpected API endpoints, especially POSTs with YAML-formatted bodies.
- Hunt for unexpected child processes spawned by the Faspex service (Java/web container) on the host.
- Review outbound network connections from the Faspex server for signs of post-exploitation or ransomware staging.
- Correlate host and network telemetry around the KEV due date window for anomalous activity on Faspex systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-47986 to the Known Exploited Vulnerabilities catalog on 21 February 2023 as "IBM Aspera Faspex Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 March 2023.
Ransomware crews whose documented playbooks reference this CVE: