CVE Vulnerabilities

CVE-2025-13211

Improper Control of Interaction Frequency

Published: Dec 11, 2025 | Modified: Dec 15, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

Weakness

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Affected Software

NameVendorStart VersionEnd Version
Aspera_orchestratorIbm4.0.0 (including)4.1.1 (excluding)

References