Impact
The vulnerability arises from improper authentication during service‑name matching in IBM i's Network Authentication Service. A remote attacker who can authenticate to the system may bypass intended security restrictions, potentially gaining elevated access or manipulating protected resources. This flaw is classified as CWE‑287, underscoring its foundation in flawed authentication logic.
Affected Systems
Affected systems include IBM i releases 7.3, 7.4, 7.5, and 7.6. The specific product is IBM i, and the impact covers all versions listed. Each of these legacy releases is vulnerable until the corresponding IBM PTF is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, though the EPSS score is not available, making it difficult to assess current exploitation likelihood. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires the attacker to possess valid credentials, but once authenticated the attacker can exploit the flaw to circumvent access controls. Prioritizing patch deployment is therefore critical.
OpenCVE Enrichment