Impact
A stack‑based buffer overflow in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 allows a remote attacker to trigger a denial of service by overflowing a buffer on the stack, causing the affected service or system to crash. The flaw is a classic CWE‑787 vulnerability that does not provide direct code execution, but it compromises availability. The impact is limited to service interruption; no privilege escalation or data exfiltration is described in the CVE text.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3 and IBM PowerVM VIOS 4.1. Specifically, AIX service packs prior to SP2, SP3, SP5, and SP13 for the respective releases, and VIOS fix packs below 4.1.0.50, 4.1.1.30, and 4.1.2.20 are impacted. Systems below these remediation levels are at risk. The recommended fix levels are AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, and VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, VIOS 4.1.0 4.1.0.50.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, with exploits likely being remote over the network, as the stack overflow occurs in a component accessible from outside. The EPSS score is not available, so the current estimate of exploit likelihood is unknown. The vulnerability is not listed in CISA KEV, suggesting no publicly known exploits yet. Attackers would need to trigger the buffer overflow, which could be achieved by sending a specially crafted request to the vulnerable service. Because the flaw only causes denial of service, the risk level is moderate without evidence of more damaging effects.
OpenCVE Enrichment