Impact
IBM AIX and PowerVM VIOS are vulnerable to a cryptographic flaw where intermediate certificate authority private keys are embedded in a publicly available update file. A remote attacker who obtains this file can extract the keys and impersonate the certificate authority used by the Non‑Interactive Management (NIM) service. This can lead to unauthorized NIM operations, such as executing privileged commands or configuring the system in ways that bypass normal security controls. The weakness is reflected by the CWE‑312 category of plaintext credential exposure.
Affected Systems
The affected products are IBM AIX versions 7.3 at Tooling Levels TL04, TL03, and TL02 with Service Packs SP2, SP3, and SP5 respectively, as well as AIX 7.2 at Tooling Level TL05 with Service Pack SP13. For PowerVM VIOS, the vulnerable Fix Packs are 4.1.2 (FP 4.1.2.20), 4.1.1 (FP 4.1.1.30), and 4.1.0 (FP 4.1.0.50). These Service Pack and Fix Pack levels are cumulative and may be applied on top of any earlier affected level within the same Tooling Level.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. Although the EPSS score is listed as < 1%, suggesting a low probability of exploitation, the vulnerability’s impact is high because the private keys are reachable from any system with network access to the update repository. The vulnerability does not appear in the CISA KEV catalog. To exploit it, an attacker would simply download the publicly exposed update file, use the private key material to forge NIM authentication, and then perform privileged or configuration actions. No local privileged access is required to download the file, making the attack feasible from the outside.
OpenCVE Enrichment