Impact
The vulnerability is caused by a missing authentication requirement for critical NFS functions in IBM i 7.3, 7.4, 7.5, and 7.6, allowing a remote attacker to trigger a denial of service and potentially compromise data integrity. This flaw is classified as an authentication failure (CWE-306). The attack vector is remote, requiring the attacker to send unauthenticated requests to the NFS service.
Affected Systems
IBM i versions 7.3 through 7.6 are affected. Any configuration that exposes the NFS service without proper authentication is vulnerable, regardless of the operating environment.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity, and the vulnerability is not listed in the KEV catalog. EPSS data is not available, so the probability of exploitation is unknown. The exploit requires network access to the NFS service and the ability to send unauthenticated requests, which can lead to service interruption and data corruption. Systems exposed to untrusted networks face a moderate risk.
OpenCVE Enrichment