Impact
This vulnerability arises because IBM i incorrectly validates FTP authentication commands, allowing an attacker with local access to send crafted inputs that lead to a denial of service. The improper command validation can cause the FTP service to fail or become unresponsive, effectively disrupting applications that rely on file transfers. The weakness corresponds to command injection style flaws (CWE‑78) and results in loss of availability for the affected system.
Affected Systems
Affected components are IBM i operating systems – specifically releases 7.6, 7.5, 7.4, and 7.3. Systems running any of these versions are at risk until the appropriate product fix (patches SJ11371 for 7.6, SJ11382 for 7.5, SJ11383 for 7.4, or SJ11384 for 7.3) is applied. The vulnerability is limited to the local scope and affects the FTP service and any processes that interact with it.
Risk and Exploitability
The CVSS base score is 5.4, indicating a moderate impact when exploited. Because the flaw requires local access, the attack vector is limited to users who can execute commands or maintain privileged console access on the IBM i host. The EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Nonetheless, any local attacker who can send malformed FTP authentication requests can trigger a crash or hang of the FTP service, causing downtime until the patch is applied.
OpenCVE Enrichment