Impact
The flaw is a stack‑based buffer overflow that permits a remote attacker to execute arbitrary code on affected IBM AIX and PowerVM VIOS systems. This vulnerability is identified as CWE‑121. Unauthorized code execution could compromise the confidentiality, integrity, and availability of the affected servers.
Affected Systems
The vulnerability affects IBM AIX releases 7.2 and 7.3 as well as the corresponding Technical Level updates: AIX 7.3 TL 04 SP 2, TL 03 SP 3, TL 02 SP 5, and 7.2 TL 05 SP 13. It also impacts IBM PowerVM VIOS 4.1.0, 4.1.1, and 4.1.2. The applicable Service Packs and Fix Packs include SP2 for AIX 7.3, SP3 for newer AIX 7.3 releases, SP5 for older 7.3, SP13 for AIX 7.2, and VIOS Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that a public exploit has not been documented. However, the description explicitly states that a remote attacker can execute arbitrary code, meaning the attack vector is remote. The vulnerability is highly valuable to attackers because it allows full control over the affected systems. Prompt remediation by installing the listed Service Packs or Fix Packs is strongly recommended to mitigate the risk.
OpenCVE Enrichment