# CVE-2025-33136

## Summary

- **CVE ID:** CVE-2025-33136
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N)
- **CWE:** CWE-471
- **Published:** May 22, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

## Affected Products

- IBM — Aspera Faspex (5.0.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7234114)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 26.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._