Impact
The vulnerability is a stack-based buffer overflow that can be triggered by a remote host, allowing an attacker to execute arbitrary code on affected IBM AIX and PowerVM VIOS systems. This flaw compromises confidentiality, integrity, and availability by granting unrestricted control over the operating system. The weakness corresponds to CWE‑787, unsanitized buffer usage.
Affected Systems
Affected products include IBM AIX 7.2 and 7.3. Vulnerable service packs include AIX 7.2 TL05 SP13 and AIX 7.3 TL04 SP2, TL03 SP3, and TL02 SP5. IBM PowerVM VIOS 4.1 is vulnerable in all versions, with fix pack levels 4.1.0.50, 4.1.1.30, and 4.1.2.20. The CVE applies to all versions listed in the CNA affected‑version list and corresponding CPE entries.
Risk and Exploitability
The severity score is 9.8 on CVSS, indicating a critical risk. Based on the description, it is inferred that the attacker can exploit the flaw through a network interface. EPSS is not available and the issue is not listed in the CISA KEV catalog. Exploitation likely requires network access to an exposed interface; a reboot of the LPAR is needed to complete the update, though Live Update can bypass a reboot on AIX. The open nature of the buffer overflow means that, if not patched, attackers can achieve full system compromise.
OpenCVE Enrichment