CVE-2023-37401
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedIBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · moderate confidenceIBM Aspera Faspex versions 5.0.0 through 5.0.3.1 includes an overly permissive cross-domain policy file (crossdomain.xml or clientaccesspolicy.xml) that lists domains which should not be trusted, potentially allowing those untrusted domains to make cross-domain requests to the Faspex application.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data>= 5.0.0, < 5.0.14CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- Low
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Check installed Aspera Faspex versionLocate and inspect the Faspex version information, typically found in the application metadata, about page, or version file within the installation directoryAffected if installed version is >= 5.0.0 and < 5.0.14
-
Locate cross-domain policy filesFind crossdomain.xml and clientaccesspolicy.xml files in the Faspex web application root directory or configuration directoryAffected if policy files exist and contain entries for untrusted domains
-
Inspect crossdomain.xml contentsOpen and read the crossdomain.xml file, examining the <allow-access-from> elements for any domain entriesAffected if file contains domain entries that are not trusted or should not have cross-domain access
-
Inspect clientaccesspolicy.xml contentsOpen and read the clientaccesspolicy.xml file, examining the <access> elements for any domain entriesAffected if file contains domain entries that are not trusted or should not have cross-domain access
-
Verify domain trust statusReview all domains listed in the policy files and compare against a list of known, legitimate, controlled domains for your organizationAffected if any untrusted or unknown domains are present in the policy files allowing cross-domain requests
User is affected if running Aspera Faspex version 5.0.0 through 5.0.13.x and the crossdomain.xml or clientaccesspolicy.xml file contains untrusted or unknown domains that should not have cross-domain access to the application
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped5.0.14
Review and restrict the cross-domain policy file to remove untrusted domains, limiting access only to legitimate, controlled domains.
IBM Aspera Faspex 5.0.14 or later
- Backup current IBM Aspera Faspex configuration and data
- Review IBM Aspera Faspex 5.0.14 release notes for any specific upgrade requirements
- Ensure system meets prerequisites for version 5.0.14
- Download IBM Aspera Faspex version 5.0.14 or later from IBM fix central or authorized distribution channel
- Stop Aspera Faspex services before upgrade
- Perform upgrade following IBM installation/upgrade documentation
- Verify cross-domain policy file (crossdomain.xml) no longer contains untrusted domains after upgrade
- Restart Aspera Faspex services
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation2.0 h
- Implementation2.0 h
- Testing1.0 h
- Review / QA1.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,744.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2023-37401 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2023-37401 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data