Impact
The vulnerability enables a remote attacker to trigger uncontrolled resource consumption, resulting in a denial of service that can affect the entire system’s availability. This flaw is based on improper resource management (CWE‑400) and can be exploited without needing privileged access, leading to service degradation or interruption.
Affected Systems
The affected products are IBM AIX (versions 7.2 and 7.3) and IBM PowerVM VIOS (version 4.1). IBM recommends applying the corresponding Service Packs for AIX (TL04 SP2, TL03 SP3, TL02 SP5, and TL05 SP13) and the relevant Fix Packs for VIOS (4.1.0.50, 4.1.1.30, and 4.1.2.20). These updates are cumulative and include fixes for all previously published security vulnerabilities.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of 0.00549 indicates a very low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. The attack is remote, likely exploiting a lack of resource limitation controls, and can cause an outage of services. The low EPSS score suggests that exploitation might require custom or zero‑day techniques, but the high severity still warrants prompt remediation.
OpenCVE Enrichment