Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain an issue that allows a remote authenticated attacker to inject special elements into operating‑system commands. The flaw stems from improper neutralization of command‑line arguments, which permits the attacker to execute arbitrary system commands. Successful exploitation would give the attacker full control over the affected system, compromising confidentiality, integrity and availability.
Affected Systems
The vulnerability applies to all IBM AIX releases prior to the Service Packs listed for remediation, including AIX 7.2 before Service Pack TL05 SP13 and AIX 7.3 before Service Packs TL04SP2, TL03SP3 or TL02SP5. It also affects IBM PowerVM VIOS 4.1 before Fix Packs 4.1.0.50, 4.1.1.30 or 4.1.2.20. These patches are cumulative and can be applied on top of any earlier affected level.
Risk and Exploitability
With a CVSS score of 9.9 the issue is classified as critical. The EPSS score is < 1%, indicating a low but nonzero probability of exploitation, and the absence of a KEV listing does not reduce the need for urgency. The attack requires remote authentication but gives the attacker arbitrary command execution via a crafted command line, typically over the network. IBM has no public exploit available yet, yet the high impact warrants rapid patching.
OpenCVE Enrichment