Impact
IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1 contain command‑injection flaws that enable a remote attacker to run arbitrary system commands with elevated privileges. The vulnerability allows the attacker to escape normal security controls and gain full control over the affected platform, threatening confidentiality, integrity, and availability.
Affected Systems
IBM AIX 7.2 and 7.3, encompassing all service packs from 7.2 TL 05 SP13 through 7.3 TL 04 SP2, are affected. PowerVM VIOS 4.1, covering release points 4.1.0, 4.1.1, and 4.1.2, is likewise vulnerable. The remediation levels include AIX SP2, SP3, SP5, or SP13 and VIOS FP 4.1.0.50, 4.1.1.30, or 4.1.2.20, which resolve all published weaknesses for these products.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score of <1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation yet. Based on the description, it is inferred that the attack vector involves remote services or management interfaces that accept untrusted input, allowing the attacker to inject system commands. Because command injection can lead to full system compromise, the risk to affected environments is significant and demands immediate remediation.
OpenCVE Enrichment