Impact
This vulnerability arises from an improper validation of TLS certificates in the NIM component of IBM AIX 7.2 and 7.3, as well as PowerVM VIOS 4.1. Because the client does not correctly verify certificates presented by the server, a remote attacker can establish an authenticated session or otherwise gain privileged access to the affected system. The flaw is rated CVSS 8.1, indicating a high severity impact on confidentiality and integrity of the system when exploited. No denial‑of‑service effect is explicitly described, but the unauthorized access could allow the attacker to run commands, read data, or modify system state.
Affected Systems
IBM AIX versions 7.2 and 7.3 are affected. The specific cumulative fix levels recommended by IBM include AIX 7.3 Service Pack 2 (TL04SP2), 7.3 Service Pack 3 (TL03SP3), 7.3 Service Pack 5 (TL02SP5), and AIX 7.2 Service Pack 13 (TL05SP13). IBM PowerVM VIOS 4.1 is also impacted, with recommended fix packs covering VIOS 4.1.0 (4.1.0.50), 4.1.1 (4.1.1.30), and 4.1.2 (4.1.2.20). The affected ranges map to the CPEs for IBM AIX 7.2.x and 7.3.x and IBM PowerVM VIOS 4.1.x.
Risk and Exploitability
The exploitation vector is remote, requiring network connectivity to the NIM service over TLS. Because the flaw allows arbitrary certificate acceptance, an attacker can impersonate the NIM server or establish a session without proper authentication. The EPSS score is 0.00318 (≈0.318%), indicating a very low but nonzero probability that the vulnerability will be exploited. The high CVSS score of 8.1, combined with the lack of a KEV listing, suggests a moderate to high threat potential. Organizations that expose NIM over the network or rely on untrusted certificates face the highest risk, and the lack of additional constraints in the description increases the likelihood of a successful attack.
OpenCVE Enrichment