Impact
The vulnerability affects IBM AIX 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1, allowing a remote authenticated attacker to execute arbitrary commands on the operating system by using improperly neutralized special elements in OS command strings. This results in full remote code execution, compromising the confidentiality, integrity, and availability of the affected systems. The weakness is an operating system command injection flaw, identified as CWE‑78.
Affected Systems
Affected products include IBM AIX 7.2 and 7.3 with service packs below AIX 7.3 TL04, AIX 7.3 TL03, AIX 7.3 TL02, and AIX 7.2 TL05 SP13, as well as IBM PowerVM VIOS 4.1 in versions 4.1.0, 4.1.1, and 4.1.2. IBM has assigned specific Service Packs (AIX SP2 for TL04, SP3 for TL03, SP5 for TL02, and SP13 for TL05) and VIOS Fix Packs (4.1.2.20, 4.1.1.30, and 4.1.0.50) that provide the necessary fixes.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score is not available, so the current probability of exploitation cannot be quantified. No active exploit is listed in the CISA KEV catalog, which suggests that no publicly reported exploitation is known. However, the vulnerability requires authentication on the target, meaning that compromised credentials or privileged accounts could be used to launch the attack. IBM recommends immediate remediation by applying the specified Service Pack or Fix Pack; a system reboot is required for offline updates unless AIX Live Update is used, and additional steps are needed to migrate Postgres15 for VIOS 4.1.0 and 4.1.1 after applying the patches.
OpenCVE Enrichment