Impact
The vulnerability allows a remote attacker to execute arbitrary commands on IBM AIX 7.2 and 7.3 or IBM PowerVM VIOS 4.1 by supply of specially crafted input that is not properly neutralized before being passed to the operating system command interpreter. This flaw gives the attacker full control over the affected machine, enabling data theft, modification, or denial of service.
Affected Systems
IBM AIX versions 7.2 (service packs up to SP13) and 7.3 (service packs up to TL04 SP2, TL03 SP3, TL02 SP5, TL05 SP13) are affected. IBM PowerVM VIOS 4.1 series – 4.1.0, 4.1.1, and 4.1.2 – are also impacted; the specific fix packs are 4.1.0 → 4.1.0.50, 4.1.1 → 4.1.1.30, and 4.1.2 → 4.1.2.20.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity RCE risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly documented exploit at this time. The attack vector is remote; an external user with network access to the affected system can deliver the crafted input through interfaces that invoke OS commands, resulting in full control of the target.
OpenCVE Enrichment