CVE Vulnerabilities

CVE-2025-13148

Unverified Password Change

Published: Dec 11, 2025 | Modified: Dec 15, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

NameVendorStart VersionEnd Version
Aspera_orchestratorIbm4.0.0 (including)4.1.1 (excluding)

Potential Mitigations

References