Impact
The vulnerability is a buffer overflow that can be triggered remotely and allows an attacker to execute arbitrary code on IBM AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1. Exploiting the flaw could give the attacker full system control, compromising confidentiality, integrity, and availability of the affected host.
Affected Systems
The flaw affects IBM AIX releases 7.2 and 7.3, as well as PowerVM VIOS 4.1. The affected AIX service packs include AIX 7.3 TL04SP2, AIX 7.3 TL03SP3, AIX 7.3 TL02SP5, and AIX 7.2 TL05 SP13. For VIOS the remediation levels are VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the remote execution potential and lack of detection make it a significant risk. Exploitation requires an attacker to send a specially crafted request to the vulnerable system; no public exploit is currently documented, so the primary mitigation is to apply the IBM APARs and service or fix packs as soon as feasible.
OpenCVE Enrichment