Impact
The vulnerability is a stack buffer overflow (CWE‑787) in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 that allows a remote attacker to trigger a denial of service. By sending crafted input to affected functions, the exploit overflows a stack buffer, causing the target process to crash and rendering the affected service unavailable. The impact is loss of availability for the affected system or service, and could disrupt business operations if the service is critical. No compromise of confidentiality or integrity is reported by the description.
Affected Systems
Affected systems include IBM AIX operating system versions 7.2 and 7.3 and IBM PowerVM VIOS version 4.1. The specific service packs and fix packs that address the flaw are: for AIX, SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, and SP13 for AIX 7.2 TL05; for VIOS, fix pack 4.1.2.20 for VIOS 4.1.2, fix pack 4.1.1.30 for VIOS 4.1.1, and fix pack 4.1.0.50 for VIOS 4.1.0. All cumulative updates include this security fix, and the patches can be applied to any earlier affected level of the target platform.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. The EPSS score is not publicly available, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is remote, with no privilege escalation or authentication required. An attacker possessing network visibility can trigger the overflow by sending a specially crafted request to the vulnerable component, causing the service to crash. While the chance of real‑world exploitation is uncertain without EPSS data, the high CVSS and lack of mitigation in unsupplemented systems warrant immediate patching.
OpenCVE Enrichment