Impact
The vulnerability is an integer overflow that can be triggered by a remote attacker, causing a denial of service by crashing a process or the entire system. It does not affect confidentiality or integrity, but it can interrupt critical operations and services.
Affected Systems
The affected products are IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. All releases prior to the Service Pack and Fix Pack levels listed by IBM are vulnerable. For AIX, the recommended remediation levels are: SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, and SP13 for AIX 7.2 TL05. For VIOS, the fix packs that address the issue are: 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, and 4.1.0.50 for VIOS 4.1.0.
Risk and Exploitability
The CVSS score of 7.5 classifies this as High severity, and the description indicates a remote attack vector. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, which suggests that widespread exploitation has not yet been reported. An attacker who succeeds in triggering the integer overflow would be able to crash targeted services or the entire system, leading to a denial of service that could disrupt business continuity. The exploit does not appear to provide further privileges or confidentiality compromise, but the impact is still significant given the potential for prolonged outage.
OpenCVE Enrichment