Impact
AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an uncontrolled resource consumption flaw that can be triggered by a remote attacker to force the system into a denial of service state. The vulnerability allows an attacker to cause excessive CPU, memory or disk usage until services become unavailable, potentially impacting availability of the operating system and any services hosted on the affected nodes. The weakness is identified as CWE-400: Uncontrolled Resource Consumption.
Affected Systems
Affected products include IBM AIX 7.2 and 7.3 (all minor revisions at the time of the advisory) and IBM PowerVM VIOS 4.1.x. The specific remediation levels are AIX 7.3 TL04 SP2, 7.3 TL03 SP3, 7.3 TL02 SP5, 7.2 TL05 SP13 and VIOS 4.1.2 4.1.2.20, 4.1.1 4.1.1.30, and 4.1.0 4.1.0.50.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity impact, and the vulnerability is exploitable remotely without authentication. EPSS data is not available, but the lack of listing in CISA KEV suggests no confirmed public exploitation yet. However, the nature of the resource consumption flaw and remote attack vector imply that attackers with network access to the affected host could readily trigger the denial of service. An LPAR reboot is required for the update unless the live update mechanism is used on AIX. The advisory emphasizes that the fix is cumulative and covers all prior known security issues.
OpenCVE Enrichment