Impact
The vulnerability arises from improper neutralization of special elements used in an OS command within IBM AIX and PowerVM VIOS NIM, allowing a remote authenticated attacker to execute arbitrary commands. This deficiency can lead to full compromise of the affected host, exposing confidential data, tampering with system integrity, and potentially disrupting availability. The associated CWE-78 and a CVSS score of 9.9 indicate a critical risk.
Affected Systems
AIX version 7.2 and 7.3 and PowerVM VIOS 4.1 are impacted. For AIX, affected releases span Service Pack levels AIX 7.3 TL 04 SP2, TL 03 SP3, TL 02 SP5, TL 05 SP13, and AIX 7.2 TL 05 SP13. For PowerVM VIOS, the vulnerable Fix Packs are VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. All listed Service Packs and Fix Packs are cumulative and include this fix as well as previous security patches.
Risk and Exploitability
The CVSS score of 9.9 signals critical severity. The EPSS score, at approximately 0.8%, indicates that exploitation is currently considered unlikely but still plausible. The vulnerability remains unlisted in CISA KEV. Exploitation requires remote authenticated access to the NIM interface; once authenticated, an attacker can run arbitrary OS commands. A successful exploit could lead to full host compromise, data exfiltration, integrity attacks, or service disruption, and a LPAR reboot is needed to complete the patch, causing a brief interruption. In environments lacking remediation, the flaw could serve as a foothold for lateral movement.
OpenCVE Enrichment