Impact
This vulnerability allows a remote unauthenticated attacker to send a crafted UDP packet to a reachable RPC service in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1, causing the target system to become completely unavailable and requiring a logical partition restart. The weakness is identified as CWE-400, and the impact is a denial of service that could disrupt critical platform operations.
Affected Systems
Affected vendors include IBM. The products impacted are IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1. Service pack and fix pack remediation levels are AIX 7.3 TL04SP2, TL03SP3, TL02SP5, AIX 7.2 TL05 SP13, and PowerVM VIOS 4.1.2 4.1.2.20, 4.1.1 4.1.1.30, and 4.1.0 4.1.0.50. These updates are cumulative and can be applied on top of any earlier affected level. No additional version details are supplied beyond the listed SP/FP names.
Risk and Exploitability
The CVSS score of 7.5 places this issue in the high‑severity range. The EPSS score of 1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly recorded exploits at this time. Nonetheless, the attack requires only a UDP packet to a reachable RPC service and no authentication, so any affected system is susceptible. Recovery is costly, as the LPAR must be restarted, which further disrupts availability.
OpenCVE Enrichment