Impact
The vulnerability is an integer overflow (CWE-190) within IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1. Based on the description, it is inferred that a remote attacker could supply crafted input over the network that triggers the overflow, causing the operating system or hypervisor to crash or become unresponsive, and thereby denying service to all dependent applications and users. The flaw does not provide attackers with elevated privileges or data exfiltration capabilities, so its primary impact is availability.
Affected Systems
Affected assets include all IBM AIX releases 7.2 and 7.3 on any service level prior to the cumulative Service Packs AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13. IBM PowerVM VIOS 4.1 is impacted on any sub‑release that has not yet applied the listed Fix Packs—VIOS 4.1.2 FP4.1.2.20, VIOS 4.1.1 FP4.1.1.30, or VIOS 4.1.0 FP4.1.0.50.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS data is currently unavailable, and the vulnerability is not catalogued in CISA’s KEV list, implying that widespread exploitation has not been observed. The likely attack vector is remote network-based delivery of malformed input, which can trigger the overflow without needing privileged access, resulting in a denial of service. Because the defect only disrupts availability, the risk to confidentiality and integrity is low, but the potential impact on mission‑critical services can be significant.
OpenCVE Enrichment