Impact
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allow a remote attacker to intercept sensitive messages and forge replies, exposing confidential data and potentially enabling malicious manipulation of communication. The flaw is classified as CWE-200, representing an exposure of sensitive information that can compromise confidentiality and permit integrity violations through forged responses.
Affected Systems
Affected products include IBM AIX versions 7.2 and 7.3 (up to TL04) and IBM PowerVM VIOS 4.1 (up to 4.1.2). IBM recommends applying the AIX Service Packs listed—SP13 for 7.2 TL05, SP2 for 7.3 TL04, SP3 for 7.3 TL03, and SP5 for 7.3 TL02—as well as the PowerVM VIOS Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20, which are cumulative and correct the exposure across all previous releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS data is unavailable, and the issue is not listed in CISA’s KEV catalog, suggesting exploitation may be possible but not widely reported. Remote attackers with network access to the affected system could utilize the messaging flaw to intercept traffic and replay or forge messages; this likely requires standard network privileges rather than privileged local access.
OpenCVE Enrichment