Impact
This vulnerability is an out-of-bounds read that can be triggered remotely, enabling an attacker to read memory beyond the intended bounds. The flaw can expose sensitive data to the attacker and may also lead to a denial of service if the exploit is performed repeatedly. The weakness is described by CWE-125.
Affected Systems
IBM AIX operating systems 7.2 and 7.3 with service packs through AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13, as well as IBM PowerVM VIOS 4.1 with fix packs 4.1.0.50, 4.1.1.30, and 4.1.2.20 are vulnerable. All earlier versions remain affected.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, and the EPSS score is not provided, so the current exploitation probability is unknown but the vulnerability is publicly disclosed. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can reach the vulnerable services over the network, likely through exposed management interfaces. Mitigation requires installing the cumulative service pack or fix pack and rebooting the system; AIX can use Live Update to avoid a restart.
OpenCVE Enrichment