<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Aspera Faspex 5 (5.0.0 Through 5.0.15.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/aspera-faspex-5-5.0.0-through-5.0.15.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 28 Jul 2026 21:20:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/aspera-faspex-5-5.0.0-through-5.0.15.4/feed.xml" rel="self" type="application/rss+xml"/><item><title>IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)</title><link>https://feed.craftedsignal.io/briefs/2026-07-ibm-aspera-faspex-rce/</link><pubDate>Tue, 28 Jul 2026 21:20:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-ibm-aspera-faspex-rce/</guid><description>A critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.</description><content:encoded><![CDATA[<p>A critical remote code execution (RCE) vulnerability, identified as CVE-2026-14958, affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4. This flaw stems from improper neutralization of special elements used in OS commands, specifically &quot;unquoted shell interpolation&quot; (CWE-78), allowing a remote authenticated attacker to execute arbitrary code. With a CVSS v3.1 base score of 9.1 (Critical), successful exploitation could lead to full system compromise, data exfiltration, or denial of service. The vulnerability requires prior authentication, meaning an attacker would need valid credentials to leverage this weakness. IBM has released a security advisory and urges users to update their installations to mitigate this risk.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>A remote attacker obtains valid authentication credentials for an IBM Aspera Faspex 5 instance, potentially through social engineering, brute-forcing, or exploiting other weaknesses.</li>
<li>The authenticated attacker crafts a malicious HTTP request to a vulnerable endpoint within the Faspex 5 application.</li>
<li>This request contains specially crafted input with shell metacharacters (e.g., <code>&amp;</code>, <code>|</code>, <code>;</code>, <code>$()</code>, <code>`</code>) embedded within parameters expected to be processed by an underlying shell.</li>
<li>Due to &quot;unquoted shell interpolation,&quot; the Faspex 5 application incorporates the malicious input directly into an OS command without proper sanitization.</li>
<li>The application executes the constructed command, leading to the execution of the attacker's arbitrary code on the underlying server.</li>
<li>The executed arbitrary code can be used to establish persistence, elevate privileges, download and install additional malware, or exfiltrate sensitive data.</li>
<li>Ultimately, the attacker achieves full compromise of the IBM Aspera Faspex 5 server and potentially gains access to hosted data and connected systems.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-14958 allows a remote authenticated attacker to execute arbitrary code on the server hosting IBM Aspera Faspex 5. This could lead to complete compromise of the server, enabling attackers to steal sensitive data, deploy ransomware, disrupt services, or use the compromised server as a pivot point for further attacks within the organization's network. The critical CVSS v3.1 score of 9.1 reflects the severe consequences, including high impacts on confidentiality, integrity, and availability, if the vulnerability is successfully exploited.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-14958 immediately by updating IBM Aspera Faspex 5 to a fixed version beyond 5.0.15.4 as per IBM's advisory referenced in this brief.</li>
<li>Deploy the Sigma rule &quot;Detect CVE-2026-14958 Exploitation - Aspera Faspex 5 OS Command Injection&quot; to your SIEM and monitor web server logs for suspicious HTTP requests.</li>
<li>Implement robust input validation and output encoding for all user-supplied data, especially in applications like IBM Aspera Faspex 5 that interact with system shells.</li>
<li>Monitor for network connections initiated from the IBM Aspera Faspex 5 server to unusual external IP addresses or domains, as these could indicate successful code execution and C2 activity.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>vulnerability</category><category>os-command-injection</category><category>web-application</category></item></channel></rss>