Impact
An uninitialized stack pointer flaw in IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 allows a remote attacker, without authentication, to trigger a crash or halt of critical system components, resulting in a complete denial of service for the affected host or service. The weakness is classified as CWE‑908 and can be exercised by sending specially crafted traffic or otherwise exploiting the stack usage path.
Affected Systems
Affected products are IBM AIX 7.2 and 7.3 operating systems and IBM PowerVM VIOS 4.1 appliance software (4.1.0, 4.1.1, 4.1.2). Versions prior to the published Service Pack or Fix Pack levels are vulnerable: for AIX, Service Packs 7.3 TL04SP2, 7.3 TL03SP3, 7.3 TL02SP5 and 7.2 TL05 SP13; for VIOS, Fix Packs 4.1.2 4.1.2.20, 4.1.1 4.1.1.30 and 4.1.0 4.1.0.50.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and no EPSS score is reported. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation through network interfaces that process untrusted data, allowing an attacker to overflow or misdirect an uninitialized stack pointer and trigger a crash. The impact is loss of availability for the affected system components, potentially bringing down critical services or an entire logical partition.
OpenCVE Enrichment