Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 are vulnerable to an improper authentication flaw that allows an attacker to read files from NFS‑exported file systems. The weakness, classified as CWE‑287, permits unauthorized data disclosure without requiring valid credentials. As a result, a competing environment or untrusted user could obtain confidential or configuration information that resides on privileged file shares, thereby compromising data confidentiality and potentially enabling further lateral movement.
Affected Systems
The affected lines of business are IBM AIX 7.2 and 7.3, including all Service Packs up to TL05 SP13, and IBM PowerVM VIOS 4.1, with Fix Packs up to 4.1.2.20. Users running these platforms before the listed SP/FP levels are exposed; newer cumulative service packs or fix packs mitigate the flaw.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity vulnerability. Exploitation requires remote network access to a host exposing NFS, and the EPSS score of 0.00503 reflects a low but non‑zero exploitation probability, with no evidence indicating current widespread exploitation. The vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. Regardless, the combination of remote access and file disclosure warrants urgent attention.
OpenCVE Enrichment