Impact
The vulnerability arises from a NULL pointer dereference that can be triggered by a remote attacker, resulting in a denial of service. The effect is that the affected system may become non‑responsive or crash within the compromised component, leading to interruption of services or processes. The weakness is classified as CWE-476 – Dereference of a NULL Pointer.
Affected Systems
IBM AIX versions 7.2 and 7.3 and IBM PowerVM VIOS version 4.1 are affected. Specific service packs for AIX such as SP2, SP3, SP5, SP13 and corresponding VIOS fix packs like 4.1.0.50, 4.1.1.30, 4.1.2.20 provide the required fixes.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. No EPSS value is available, and it is not listed in the CISA KEV catalog, implying no current evidence of exploitation in the wild. The likely attack vector is remote network access where an attacker may send crafted data to trigger the null dereference. Even though the impact is limited to denial of service rather than data theft or control, the inability to reboot the system without interrupting services can be significant in mission‑critical environments.
OpenCVE Enrichment