Impact
A crafted Router Advertisement can trigger command injection on IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1, allowing a remote attacker to execute arbitrary code without authentication. The vulnerability involves improper privilege management as identified by CWE‑269. Successful exploitation would compromise confidentiality, integrity, and availability of the affected systems at the host level.
Affected Systems
IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 are impacted. The remediation levels correspond to AIX Service Packs SP13 for 7.2, SP5 for 7.3, and VIOS Fix Packs 4.1.2.20, 4.1.1.30, and 4.1.0.50 for VIOS 4.1, all of which include cumulative fixes for this and prior security issues.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity; the EPSS score is <1%, but the vulnerability is exploitable over the network via Router Advertisements, which a remote attacker can send without credentials. It is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet, yet the lack of authentication makes it a significant risk to any exposed system.
OpenCVE Enrichment