Impact
The vulnerability in IBM AIX 7.2 and 7.3 and PowerVM VIOS 4.1 allows a remote attacker to gain root privileges due to improper authentication, a classic authentication bypass (CWE-287). If exploited, an attacker would obtain unrestricted control over the operating system or virtual machine.
Affected Systems
Affected systems include IBM AIX 7.2 and 7.3 across all sub‑versions, as well as IBM PowerVM VIOS 4.1.0 through 4.1.2. The most recent impacted releases are covered by AIX Service Packs TL04SP2, TL03SP3, TL02SP5, and TL05 SP13. All available Service Packs and Fix Packs are cumulative.
Risk and Exploitability
Risk is high, with a CVSS score of 9.8 indicating critical severity. The EPSS score is less than 1%, and the flaw is not listed in the CISA KEV catalog, yet the ability to gain full root access remotely makes it a priority for immediate remediation. Exploitation requires network reachability to the affected server and the ability to initiate authentication; no local privilege is required. Because the attack vector is remote, patching should be prioritized immediately.
OpenCVE Enrichment