Impact
This issue is a stack-based buffer overflow (CWE‑121) that permits a local attacker on an IBM AIX or PowerVM VIOS system to execute arbitrary code. An attacker who can run code with local privileges can manipulate the vulnerable buffer to inject and run code with the same user or kernel level permissions, effectively taking control of the affected system.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. The advisory lists specific Service Packs for AIX (AIX 7.3 TL04SP2, AIX 7.3 TL03SP3, AIX 7.3 TL02SP5, AIX 7.2 TL05 SP13) and Fix Packs for VIOS (VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, VIOS 4.1.0 4.1.0.50).
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity vulnerability. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. Because the flaw requires local access and exploits a buffer overflow, the attack vector is local; however, once executed it can compromise confidentiality, integrity, and availability by providing the attacker arbitrary code execution on the system.
OpenCVE Enrichment