Impact
The vulnerability permits a remote attacker to bypass authentication mechanisms and execute arbitrary commands within IBM AIX and PowerVM VIOS, resulting in full control of the affected host. This weakness is classified as Improper Authentication (CWE‑287) and carries a CVSS base score of 9.8, indicating a critical severity.
Affected Systems
IBM AIX 7.2 and 7.3 are affected, with remedial levels ranging from AIX 7.3 TL02SP5 through 7.3 TL04SP2 and AIX 7.2 TL05SP13. IBM PowerVM VIOS 4.1 requires updating to at least Fix Pack 4.1.0.50 for the 4.1.0 line, FP 4.1.1.30 for the 4.1.1 line, and FP 4.1.2.20 for the 4.1.2 line. All patches are cumulative and can be applied on top of earlier service or fix packs.
Risk and Exploitability
The CVSS score of 9.8 demonstrates a highly severe risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can exploit this flaw remotely by sending crafted requests that trigger the authentication bypass; the vulnerability affects any system exposed to the network regardless of local user privileges, leading to total compromise of the host.
OpenCVE Enrichment