US reports exploitation of critical vulnerabilities in IBM Aspera Faspex and Mitel MiVoice
Attackers are actively exploiting critical vulnerabilities in IBM Aspera Faspex and Mitel MiVoice Connect to attack organizations, the Cybersecurity and Infrastructure Security Agency (CISA) of the US Department of Homeland Security warns. This would include ransomware attacks. IBM Aspera Faspex is a web-based file exchange application running on an Aspera server. On January 26, IBM released a security update for a critical vulnerability in Aspera Faspex, identified as CVE-2022-47986 . By sending a specially crafted API call, an attacker can execute arbitrary code on the system. The impact of the vulnerability was rated on a scale of 1 to 10 with a 9.8. On February 13, the Shadowserver Foundation , a non-profit foundation registered in the Netherlands and the United States that fights botnets and cybercrime, reported that attackers are exploiting the vulnerability. The first detected attack attempts appeared to date from February 3, a week after the release of the security update. The CISA is now also reporting abuse of the Aspera leak. The US government agency also states that attackers are also exploiting two vulnerabilities in Mitel MiVoice Connect. These are CVE-2022-41223 and CVE-2022-40765 . Mitel MiVoice Connect is a voip platform for organizations that offers communication and collaboration tools through a single interface. The two Mitel vulnerabilities that the CISA is now warning of have also been found by CrowdStrike.