Impact
The vulnerability allows a remote attacker to cause a denial of service on IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1 servers due to improper handling of a missing SSL client certificate. This is a CWE-400 resource exhaustion weakness, leading to a service disruption that compromises availability of the affected system.
Affected Systems
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 are affected. The remediation levels are AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, and VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. These service packs and fix packs are cumulative, covering all previously published vulnerabilities.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, but the absence of a KEV listing suggests no known widespread attacks. The vulnerability requires remote reachability and the ability to initiate a connection that triggers the missing SSL client certificate handling, allowing an attacker to force the system to terminate services and achieve a denial of service.
OpenCVE Enrichment