Impact
This vulnerability affects IBM AIX versions 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. An improperly neutralized special element in input can cause the operating system to write data to an arbitrary file path. Because the attack may create or overwrite executables, configuration files, or other critical system files, a remote attacker can gain elevated privileges, compromise the integrity of the system, or execute arbitrary code. The weakness is classified as Input Validation (CWE-73).
Affected Systems
IBM AIX 7.2 and 7.3 TL04, TL03, TL02, and TL05 (SP13) are affected, along with IBM PowerVM VIOS 4.1.0, 4.1.1, and 4.1.2. The remediation levels are cumulative; for AIX the relevant Service Packs are SP2 for TL04, SP3 for TL03, and SP5 for TL02, while for VIOS the corresponding Fix Packs are 4.1.0.50, 4.1.1.30, and 4.1.2.20.
Risk and Exploitability
The CVSS score of 9.1 indicates a high impact and high exploitation potential. The EPSS score is not available, so the current likelihood of exploitation is uncertain. This vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote, as the description specifies a remote attacker can trigger the file overwrite through crafted input.
OpenCVE Enrichment