Impact
A buffer overflow flaw in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 permits a remote attacker to execute arbitrary code on the affected system. By overflowing a buffer, the attacker can take control of the application, compromising confidentiality, integrity and availability of the host.
Affected Systems
IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS version 4.1 are affected. These products include the core operating system components of IBM AIX and the Virtual I/O Server that runs on IBM Power Systems.
Risk and Exploitability
The CVSS score of 9.8 highlights the high severity of this remote code execution vulnerability. EPSS data is not available, so the exact exploitation likelihood is unknown, but the lack of a KEV listing does not diminish the risk. The most likely attack vector is via a network‑reachable service that allows the attacker to transmit an oversized payload, triggering the buffer overflow and gaining code execution on the host.
OpenCVE Enrichment