Impact
The vulnerability is a stack buffer overflow that is triggered by a specially crafted input from a remote authenticated attacker against IBM AIX 7.2, AIX 7.3, or PowerVM VIOS 4.1. When the overflow occurs, the attacker can execute arbitrary code with the privileges of the vulnerable service, as stated in the CVE description. The description does not explicitly state secondary consequences such as system compromise or data disclosure; such outcomes are inferred from the fact that arbitrary code execution is possible.
Affected Systems
Affect eproducts are IBM AIX version 7.2 and 7.3 (all minor releases) and IBM PowerVM VIOS 4.1 (including 4.1.0, 4.1.1, and 4.1.2). The advisory lists cumulative Service Packs for AIX (e.g., SP2 for 7.3 TL04, SP13 for 7.2 TL05) and corresponding Fix Packs for VIOS (e.g., FP 4.1.2.20 for 4.1.2, FP 4.1.1.30 for 4.1.1, FP 4.1.0.50 for 4.1.0). The remediation can be applied on top of any earlier level within the same maintenance level.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but these omissions do not reduce the potential threat. Exploitation requires the attacker to be authenticated to the system and to send a crafted input that triggers a stack buffer overflow. Once the overflow occurs, the attacker may execute arbitrary code with the service's privileges. The likely attack vector is inferred to be network‑based, as the vulnerability is triggered by remote input.
OpenCVE Enrichment