Impact
The vulnerability is a heap buffer overflow that allows a remote attacker to execute arbitrary code on IBM AIX 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. The flaw gives an attacker the ability to compromise confidentiality, integrity, and availability of the affected systems. The exploitable memory corruption could lead to full system takeover, allowing attackers to run malicious code with system privileges. The identified weakness is CWE-787.
Affected Systems
Affected vendors include IBM across its AIX operating system and PowerVM Virtual I/O Server. For AIX, versions 7.2 and 7.3 up to the referenced Service Pack levels are impacted. Specifically, AIX 7.3 TL04SP2, AIX 7.3 TL03SP3, AIX 7.3 TL02SP5, and AIX 7.2 TL05 SP13 are noted. For PowerVM VIOS 4.1, all 4.1.x releases up to 4.1.0, 4.1.1, and 4.1.2 are affected depending on the fix pack. The Fix Packs for VIOS 4.1.0 include 4.1.0.50, for 4.1.1 include 4.1.1.30, and for 4.1.2 include 4.1.2.20.
Risk and Exploitability
The CVSS base score of 9.8 places the vulnerability in the critical severity range, indicating that if exploited remotely the attacker could gain full control. The EPSS score is not available, so no current data on exploitation probability is published. The problem is not listed in the CISA KEV catalog. Attack vector is inferred to be remote, likely over the network, as the heap buffer overflow is triggered by inputs from a remote source. Because the flaw allows arbitrary code execution, the impact includes unauthorized system takeover and potential spread to other hosts in the environment.
OpenCVE Enrichment