Impact
An out‑of‑bounds write in the RFC2047 encoded‑word parser allows a remote attacker to execute arbitrary code on IBM DataPower Gateway devices. The vulnerability is caused by improper bounds checking of RFC2047 input, which can corrupt memory and lead to full system compromise. Once exploited, the attacker can gain complete control over the gateway, read and modify configuration, inject malicious traffic, and potentially pivot to other assets on the network.
Affected Systems
The defect affects IBM DataPower Gateway releases 10.5.0.0 to 10.5.0.22, 10.6.1 to 10.6.6, 10.6.0.0 to 10.6.0.10, and 11.0.0.0 to 11.0.0.2. Supported vendors include IBM, with the fixed versions being 10.6CD 10.6.1 or later, 10.6.0 10.6.0.11 or later, 11.0.0 11.0.0.3 or later, and 10.5.0 10.5.0.23 or later. These firmware upgrades incorporate the patch that eliminates the out‑of‑bounds write.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity with a high likelihood of exploitation in a real‑world attack. The EPSS score is not available, but the lack of a known CISA KEV listing does not reduce its seriousness; the vulnerability is actively exploitable by sending crafted RFC2047 messages. Remote attackers can trigger the flaw by targeting the gateway with an encoded‑word payload; no local authentication or privilege escalation is required, making the attack vector likely to be over the network. Organizations should treat this as a high‑risk condition that demands immediate action.
OpenCVE Enrichment