Impact
The vulnerability allows a local attacker to read sensitive information through an out-of-bounds memory read, which corresponds to CWE-125. An attacker can access data that should be protected, but can not directly modify or execute code on the system. The moderate CVSS score of 5.5 reflects that the impact is limited to integrity and confidentiality without a privilege escalation or remote execution component.
Affected Systems
IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, are affected. For AIX, the relevant Service Packs include SP2 for 7.3 TL04, SP3 for 7.3 TL03, SP5 for 7.3 TL02, and SP13 for 7.2 TL05; for VIOS, the Fix Packs are FP4.1.2.20, FP4.1.1.30, and FP4.1.0.50. These releases are cumulative and cover all earlier security fixes.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is listed in the CISA KEV catalog as not included, suggesting no current weaponized exploit is known. Attackers would need local access to the affected system, and the issue arises from an out-of-bounds read that could leak confidential data; there is no remote exploitation pathway disclosed.
OpenCVE Enrichment