Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a flaw that allows a remote authenticated attacker to read memory out of bounds, potentially exposing sensitive information or causing a service crash. The vulnerability is an out‑of‑bounds read, identified as CWE‑125, and can lead to both confidentiality and availability compromises.
Affected Systems
The affected products are IBM AIX 7.2 and 7.3, as well as PowerVM VIOS 4.1. For AIX, the remediation levels are AIX 7.2 TL05 SP13, AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, and AIX 7.3 TL02 SP5, which are cumulative and cover all prior fixes. For VIOS, the applicable fix packs are VIOS 4.1.0 4.1.0.50, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.2 4.1.2.20; these can be applied on top of any earlier level of the technology library.
Risk and Exploitability
The CVSS score of 7.9 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA KEV, which suggests no publicly known exploit at the time of this analysis. The attack requires remote authenticated access, implying that an attacker must have valid credentials on the target system. Once authenticated, the flaw can be exploited without privileged escalation, enabling data leakage or denial of service. The mitigation is to apply the vendor‑released fixes immediately, as described below.
OpenCVE Enrichment