Impact
This vulnerability results from an off‑by‑one error in the bounds‑checking logic of IBM AIX 7.2/7.3 and PowerVM VIOS 4.1, allowing a remote attacker to execute arbitrary code. This flaw is an Off‑By‑One Error (CWE-128). The flaw compromises confidentiality, integrity, and availability by permitting malicious code to run with the privileges of the affected process.
Affected Systems
Affected vendors are IBM for AIX 7.2 and 7.3, and PowerVM VIOS 4.1. The vendor recommends applying Service Pack 13 for AIX 7.2 and Service Pack 5 for AIX 7.3 (with cumulative updates, notably SP2 for AIX 7.3 TL04, SP3 for TL03, and SP5 for TL02). For VIOS, the vulnerability is fixed in Fix Pack 4.1.0.50, 4.1.1.30, and 4.1.2.20, which are cumulative and can be applied over earlier levels.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the overall exploitation probability remains uncertain. The likely attack vector is remote network access to the affected AIX or VIOS instance, possibly through a privileged service that performs unchecked bounds checks; successful exploitation would allow an attacker to run code with the privileges of the vulnerable process.
OpenCVE Enrichment