Impact
A path traversal weakness allows a remote attacker to provide an arbitrary pathname to a privileged service, enabling read or write access to files outside the intended restricted directory. This can lead to unauthorized disclosure of confidential data or modification of critical system files, thereby compromising integrity and confidentiality of the affected system.
Affected Systems
IBM AIX versions 7.2 and 7.3, including AIX 7.3 TL04SP2, TL03SP3, and TL02SP5, and AIX 7.2 TL05 SP13, as well as PowerVM VIOS 4.1, specifically VIOS 4.1.0 4.1.0.50, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.2 4.1.2.20. All versions listed are affected until the corresponding Service Pack or Fix Pack is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation data. The likely attack vector is remote, leveraging the ability to input a crafted path into vulnerable IBM AIX or PowerVM VIOS services. Because the flaw involves improper pathname validation, an attacker does not need elevated privileges to exploit it, making it potentially accessible to a broad threat set.
OpenCVE Enrichment