Impact
IBM AIX 7.2, 7.3 and IBM PowerVM Virtual I/O Server 4.1 have a flaw where the NIM server process crashes during client registration because of a buffer overflow. The vulnerability is a classic unsafe buffer handling issue (CWE-120). The overflow causes the NIM server to terminate, disrupting management operations and preventing new client registrations. No evidence in the CVE data indicates that the overflow leads to code execution or privilege escalation.
Affected Systems
AIX versions 7.2.0 through 7.3 and PowerVM VIOS version 4.1.0 through 4.1.2 are affected. IBM recommends applying the Service Pack or Fix Pack levels that include the fix as listed in the advisory: for AIX 7.3 TL04, apply Service Pack SP2; for AIX 7.3 TL03, apply SP3; for AIX 7.3 TL02, apply SP5; for AIX 7.2 TL05, apply SP13; for VIOS 4.1.2, apply FP4.1.2.20; for VIOS 4.1.1, apply FP4.1.1.30; for VIOS 4.1.0, apply FP4.1.0.50.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is < 1%, and the vulnerability is not listed as a KEV. The likely attack vector is remote exploitation through the NIM server, with the primary impact being service disruption: an attacker can send a crafted registration request that triggers the crash, resulting in denial of service for management functions. No evidence of code execution or privilege escalation is provided by the CVE data. IBM strongly recommends addressing the issue immediately.
OpenCVE Enrichment