Impact
IBM AIX versions 7.2 and 7.3, together with IBM PowerVM VIOS 4.1, contain an uncontrolled recursion weakness that can be triggered by a remote adversary. The flaw allows the target system to consume excessive resources and become unresponsive, consistent with CWE‑400. A CVSS score of 7.5 indicates a moderate‑to‑high severity, confirming that the vulnerability can incapacitate affected services without requiring elevated privileges.
Affected Systems
The vulnerability affects all IBM AIX 7.2 and 7.3 releases, specifically those patched by Service Packs 7.3 TL04SP2, 7.3 TL03SP3, 7.3 TL02SP5, and 7.2 TL05 SP13, and all IBM PowerVM VIOS 4.1 releases, including Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20. Updating to these cumulative SPs/FPs incorporates fixes for prior AIX/VIOS security issues.
Risk and Exploitability
The CVSS metrics reveal a notable impact, and the EPSS score of 0.00387 indicates a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, reducing visibility for immediate exploitation. Likely attack vector is remote; a malicious actor can engage the vulnerable system over the network to trigger the recursion and force a denial of service. No authentication prerequisites are described, implying that the threat could be launched by unauthenticated or minimally authenticated users.
OpenCVE Enrichment