Impact
IBM reports that an input handling flaw in AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1 can result in a null pointer dereference when a remote user sends specially crafted data. The specification that the data must be specially crafted is not explicitly stated in the description; it is inferred from the context that a remote attacker could trigger the denial of service. The vulnerability is a classic CWE‑476 condition that does not allow data exfiltration or code execution, but it can cause system instability or an unreachable state, effectively denying legitimate users from accessing the affected platform.
Affected Systems
The affected platforms are IBM AIX version 7.2 and 7.3, along with all related service packs (SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, and SP13 for AIX 7.2 TL05). IBM PowerVM VIOS 4.1 has several cumulative fix packs, including 4.1.2.20 for version 4.1.2, 4.1.1.30 for 4.1.1, and 4.1.0.50 for 4.1.0. The service packs and fix packs are cumulative, so they can be applied on top of any earlier affected level of the technical level.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, so a precise exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to send a crafted request to the vulnerable component; the exploitation would trigger the null pointer dereference and freeze or crash the system, resulting in a denial of service. No privileged or local access is required beyond remote reachability, and there is no indication of a requirement to exploit multiple machines to achieve broader impact.
OpenCVE Enrichment