Impact
A format string flaw in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows an attacker with network access to execute arbitrary code on the affected system. The weakness, classified as CWE‑134, can lead to full compromise of confidentiality, integrity and availability on both the host and any virtual machines running on it. The description explicitly states that the flaw enables arbitrary code execution if exploited.
Affected Systems
The vulnerable products are IBM AIX 7.2 and 7.3 at the specified SP/TL levels (AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13) and IBM PowerVM VIOS 4.1 at FP levels (VIOS 4.1 FP 4.1.1.30, VIOS 4.1.0 FP 4.1.0.50, VIOS 4.1.2 FP 4.1.2.20). Patching the service packs or fix packs is required to remediate the issue.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, but the vulnerability is listed as not in the CISA KEV database. The attack is likely remote, requiring connectivity to a vulnerable service or component within AIX or VIOS; the description does not detail the exact vector, so this is inferred based on the nature of format string exploits.
OpenCVE Enrichment