Impact
This vulnerability allows an authenticated user to bypass IBM i security restrictions by sending specially crafted FTP PORT and EPRT commands. The flaw lies in improper validation of these FTP commands, enabling the attacker to gain unauthorized access to internal network services. The impact includes potential elevation of privileges within the IBM i environment and can lead to further data compromise or disruption of services. The weakness is classified under CWE‑918, which covers race condition or synchronization vulnerabilities in network protocols.
Affected Systems
IBM i versions 7.3 through 7.6 are affected. Affected product lines include IBM i 7.3, 7.4, 7.5, and 7.6, all of which are listed under the vendor/product identifier IBM:i. Servers running these versions should be checked for the presence of the known PTFs (SJ11371 for 7.6, SJ11382 for 7.5, SJ11383 for 7.4, and SJ11384 for 7.3).
Risk and Exploitability
The vulnerability scores a CVSS of 6.4, indicating a moderate severity. No EPSS score is available, so the current exploit probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote and requires the attacker to be authenticated to the FTP service. The attacker must have valid FTP credentials and then issue a malformed PORT or EPRT command to take advantage of the improper validation. If successful, the attacker can cause a denial of service or bypass security restrictions, potentially exposing internal services.
OpenCVE Enrichment