Impact
IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1 suffer a stack buffer overflow that can be triggered by a remote attacker, enabling arbitrary code execution. The flaw directly compromises confidentiality, integrity, and availability, allowing an attacker to take full control of the affected system.
Affected Systems
IBM AIX 7.2 and 7.3 across all service packs, including SP13 for AIX 7.2 TL05 and SP2, SP3, SP5 for AIX 7.3 TL04, TL03, TL02 respectively. IBM PowerVM VIOS 4.1 is impacted across all fix pack levels, with remediation available in FP4.1.0.50, FP4.1.1.30, and FP4.1.2.20.
Risk and Exploitability
The CVSS score of 9.8 classifies this as critical. EPSS data is unavailable, and the vulnerability is not in the CISA KEV catalog, but that does not diminish potential risk. The flaw is exploitable over the network. The CVE description does not specify whether authentication is required; it is inferred that an attacker may not need authentication to trigger the stack buffer overflow, leading to arbitrary code execution. Exploitation would grant the attacker full control over the affected system, and remediation requires reboots for VIOS and a Live Update or reboot for AIX.
OpenCVE Enrichment