Impact
The vulnerability allows a remote attacker to obtain sensitive information because the system authentication is not enforced correctly. The issue is characterized as a weakness in authentication (CWE‑287). If exploited, the attacker could view confidential system data, potentially undermining confidentiality and exposing additional system details.
Affected Systems
IBM AIX 7.2 and 7.3 (any intermediate milestone level prior to SP13 for 7.2 or SP5 for 7.3) and IBM PowerVM VIOS 4.1 (legacy 4.1.0, 4.1.1, 4.1.2 levels) are affected. The effective remediation levels are AIX SP2 for 7.3 TL04, SP3 for 7.3 TL03, SP5 for 7.3 TL02, SP13 for 7.2 TL05, and VIOS FP 4.1.2.20, 4.1.1.30, or 4.1.0.50, all of which include cumulative fixes for this and prior vulnerabilities.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is currently not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, a remote attacker could obtain sensitive information by bypassing authentication mechanisms. The likely attack vector is remote, with the attacker needing to reach the authentication service over the network to exploit the flaw. No further exploitation prerequisites or privilege escalation steps are described in the provided data.
OpenCVE Enrichment