Impact
This vulnerability allows an attacker who can reach the affected system remotely to alter network traffic patterns and change DNS settings because the system’s authentication mechanism does not properly enforce identity checks. The flaw is classified as CWE‑287 and carries a CVSS score of 8.2, indicating that successful exploitation could compromise the integrity of network communications and provide a foothold for lateral movement or interception. The potential impact includes unauthorized routing of traffic, denial of service to legitimate services, or redirection of domain resolution to malicious endpoints, thereby affecting confidentiality, integrity, and availability of services on the compromised host.
Affected Systems
The affected software includes IBM AIX versions 7.2 and 7.3 and IBM PowerVM VIOS 4.1. For AIX, remediation is available through Service Packs such as AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13. For VIOS, Fix Packs such as VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50 provide cumulative fixes for all previously published vulnerabilities and can be applied to any earlier affected level of the technology line.
Risk and Exploitability
With a CVSS score of 8.2 the severity is high, although the EPSS score is not available, the lack of a KEV listing suggests no widely documented exploit yet. The attack vector is inferred to be remote, taking advantage of the improper authentication to gain the necessary privileges. Exploitation requires the ability to reach the system over the network and does not need local access. An LPAR reboot is required to finalize the update, although a Live Update can avoid downtime on AIX. Adhering to the documented secure nimsh protocol and migrating to Postgres15 for VIOS 4.1.x are recommended post‑update steps to ensure overall system integrity.
OpenCVE Enrichment