Impact
The vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 allows a remote attacker to execute arbitrary code by providing network‑supplied pointers that are improperly validated. This flaw can lead to full system compromise, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
Affected systems include IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1. The advisory specifies remediation through specific service packs and fix packs: AIX 7.3 TL04SP2, TL03SP3, or TL02SP5; AIX 7.2 TL05 SP13; VIOS 4.1.2 FP 4.1.2.20; VIOS 4.1.1 FP 4.1.1.30; and VIOS 4.1.0 FP 4.1.0.50. These patches are cumulative and are available from IBM Fix Central.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. EPSS data is not available, so the probability of exploitation cannot be quantified from this metric, but the vulnerability is listed as not being in CISA KEV. The flaw is a remote code execution vector that can be triggered over the network, making it highly actionable for an attacker with network access to the vulnerable host.
OpenCVE Enrichment