Impact
IBM AIX version 7.2 and 7.3, as well as PowerVM VIOS 4.1, have a flaw where special elements used in operating‑system commands are not properly neutralized. An attacker who is already authenticated can inject crafted input into a command that AIX or VIOS will execute, giving the attacker the ability to run arbitrary commands with the privileges of the affected system. The weakness is a classic command injection (CWE-78) and can lead to full system compromise, affecting confidentiality, integrity, and availability.
Affected Systems
Vulnerable products include IBM AIX versions 7.2 and 7.3, and IBM PowerVM Virtual I/O Subsystem 4.1. The IBM fix set is cumulative: for AIX, Service Pack 2 for 7.3 TL04, Service Pack 3 for 7.3 TL03, Service Pack 5 for 7.3 TL02, and Service Pack 13 for 7.2 TL05. For VIOS, Fix Pack 4.1.2.20, 4.1.1.30, and 4.1.0.50. These updates are available through Fix Central and apply to earlier affected levels of the technology stack.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical level of impact, and although no EPSS score is reported, the lack of exploitation data does not diminish the potential for exploitation in a production environment. The vulnerability requires the attacker to be authenticated, but once that state is achieved, arbitrary command execution is possible. The vulnerability is not listed in the CISA KEV catalog; however, the high severity and the ease of exploitation via supplied service packs make immediate remediation a priority.
OpenCVE Enrichment