Impact
The vulnerability is in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1's nimesis registration service, allowing a remote attacker to traverse the filesystem and overwrite arbitrary files. Overwriting files can compromise the integrity of the affected system.
Affected Systems
IBM AIX 7.2 and 7.3, any service pack lower than the cumulative SPs listed (SP2 for AIX 7.3 TL04, SP3 for 7.3 TL03, SP5 for 7.3 TL02, and SP13 for 7.2 TL05) are affected. IBM PowerVM VIOS 4.1.0 through 4.1.2, including any instance prior to the 4.1.0.50, 4.1.1.30, and 4.1.2.20 fix packs, also remain vulnerable.
Risk and Exploitability
The CVSS base score of 8.2 indicates high severity. The EPSS score of <1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack appears remote, accessed through the nimesis registration service. Exploitation requires network connectivity to the service and the ability to write to the targeted file path through path traversal.
OpenCVE Enrichment