Impact
The flaw arises from improper authentication mechanisms in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1, enabling a remote attacker to execute arbitrary code. The vulnerability allows unauthorized code execution, potentially compromising confidentiality, integrity and availability of the affected systems. It is categorized as CWE‑287, indicating weaknesses in authentication.
Affected Systems
Affected products include IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1 across all service pack or fix pack levels below the remediation thresholds listed. Recommended fixes are the AIX Service Pack SP2 for AIX 7.3 TL04, SP3 for TL03, SP5 for TL02, and SP13 for AIX 7.2 TL05, as well as the PowerVM VIOS Fix Packs 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1 and 4.1.0.50 for VIOS 4.1.0. All cumulative updates also include prior vulnerability fixes.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity level. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalogue, indicating no known public exploits yet. However, the description explicitly claims remote execution capabilities, so the attack vector is inferred to be remote. Exploitation requires bypassing authentication controls, after which an attacker can run arbitrary code with system privileges. The lack of public exploitation reports suggests this risk is primarily theoretical, yet the potential impact warrants immediate action.
OpenCVE Enrichment