Impact
A local attacker who can interact with the operating system may inject shell metacharacters into commands processed by IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1, enabling the execution of arbitrary commands. This flaw permits an attacker to run commands with the privileges of the vulnerable process, potentially compromising confidentiality, integrity, or availability of the affected system.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3 across all feature levels and IBM PowerVM VIOS version 4.1. Official remediation levels are AIX service packs SP2 for TL04, SP3 for TL03, SP5 for TL02, and SP13 for TL05; for VIOS the applicable fix packs are 4.1.0.50, 4.1.1.30, and 4.1.2.20. These are cumulative and incorporate fixes for all previously published IBM AIX/VIOS security vulnerabilities.
Risk and Exploitability
The CVSS score of 7.8 indicates a significant severity. EPSS information is not available, so the exploitation likelihood cannot be quantified. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is local, inferred from the requirement that the attacker must have local access and the ability to submit commands to the shell. Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the vulnerable process, which can lead to full system compromise if further privilege escalation is achieved.
OpenCVE Enrichment