One Shared Aspera Service Breaks Several Controls

The risk is not four separate bugs. It is one shared front-end service, asperahttpd, that sits in the path for both Endpoint and Server and can be pushed into denial of service, auth bypass, unauthorized file reads, or code execution depending on which flaw is hit. Standard patch triage that treats each CVE as an isolated control misses that the daemon itself is the blast radius. NCSC-NL says IBM fixed four flaws in IBM Aspera High-Speed Transfer Endpoint and Server 3.7.4 through 4.4.7 Fix Pack 1. The advisory maps them to path traversal, stack-based buffer overflow, heap-based buffer overflow, improper authentication, and a NULL pointer dereference in asperahttpd, with impact ranging from service crash to bypassing authorization and reading local files without permission. The practical point is that this service is a single choke point for both availability and access control. If it breaks, the transfer platform does not just fail closed; it can fail in ways that expose data or hand over control of the service itself.

Part of the PlainSec briefing for 2026-06-09

Sources