Impact
This vulnerability allows a remote attacker to trigger a denial of service by exploiting an incorrect array index boundary check in IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1. The flaw can cause the affected system to crash or become unresponsive when the vulnerable code receives malicious input.
Affected Systems
Affected products are IBM AIX versions 7.2 and 7.3 and IBM PowerVM VIOS 4.1.1 and 4.1.0. For AIX the vulnerable service packs range from SP2 to SP13, including the TL upgrades such as TL04, TL03, and TL02. The VIOS service packs that include the fix are 4.1.0.50, 4.1.1.30, and 4.1.2.20. Any system running these versions is susceptible until updated to a newer service pack or fix pack.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS score is reported and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote access to the affected software and the ability to send specially crafted input that triggers the out‑of‑bounds array access, leading to a crash or a required reboot. While no active exploitation has been noted in the KEV registry, the flaw still permits remote denial of service, potentially disrupting service availability for affected systems.
OpenCVE Enrichment