Impact
A heap buffer overflow is present in IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1, allowing a remote attacker to execute arbitrary code. The vulnerability achieved by overflowing a heap buffer can compromise the confidentiality, integrity, and availability of the affected system. The CVSS score of 8.3 indicates a high severity and the lack of an EPSS score means there is no publicly known exploitation data at this time, but the vulnerability remains a significant risk.
Affected Systems
IBM AIX 7.2 and 7.3 (including all minor releases) and IBM PowerVM VIOS 4.1.x are affected. The recommended remediation levels are AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, and VIOS 4.1.2 FP 4.1.2.20, VIOS 4.1.1 FP 4.1.1.30, and VIOS 4.1.0 FP 4.1.0.50. These service packs and fix packs are cumulative and include fixes for all previously published security vulnerabilities for the respective platforms.
Risk and Exploitability
With a CVSS score of 8.3, the vulnerability is considered high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, where an attacker can trigger the heap overflow to gain arbitrary code execution on the system. Prompt patching is essential, as exploitation would allow full compromise of the affected environment.
OpenCVE Enrichment