Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 can allow a remote attacker to compromise the confidentiality and integrity of the system due to an out‑of‑bounds write. The vulnerability is classified as CWE‑787 and is rated with a CVSS score of 7.7, indicating a high potential for damage. It could permit the attacker to read or modify protected data on the affected systems.
Affected Systems
Affected vendors and products include IBM AIX versions 7.2 and 7.3 (specifically the 7.3 TL 04 SP 2, 7.3 TL 03 SP 3, 7.3 TL 02 SP 5, 7.2 TL 05 SP 13) and IBM PowerVM VIOS 4.1, with the recommended remediation levels being VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. The advisory notes that these service packs and fix packs are cumulative and include all prior fixes, and they can be applied to any earlier affected major release.
Risk and Exploitability
The high CVSS score of 7.7 reflects a significant risk, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Attackers with network access to the AIX or VIOS environment could use the flaw to execute an out‑of‑bounds write, thereby compromising confidentiality and integrity. No publicly available exploit code is mentioned, but the nature of the weakness indicates that a crafted input could trigger the vulnerability. Immediate patching is recommended to mitigate this risk.
OpenCVE Enrichment