Impact
IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 contain a stack buffer overflow that can be triggered by a remote authenticated attacker. The flaw allows execution of arbitrary code with the privileges of the affected service, which can lead to full system compromise, unauthorized data disclosure, configuration tampering, and potential denial‑of‑service by exhausting system resources.
Affected Systems
Affected products are IBM AIX 7.2 and 7.3 (including all minor releases) and IBM PowerVM VIOS 4.1 (versions 4.1.0, 4.1.1 and 4.1.2). The remediation requires installing the IBM Service Packs or Fix Packs listed in the advisory, which are cumulative and contain fixes for these and earlier vulnerabilities.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of publicly known exploits does not reduce the risk. Based on the description, exploitation requires the attacker to be authenticated to the target system and to provide a specially crafted input that triggers the stack buffer overflow. Adhering to the provided fix sequence and reboot requirements mitigates the known exploitation vector.
OpenCVE Enrichment