Impact
IBM’s cmdnim component contains a flaw that lets an unprivileged local user execute arbitrary payloads with root privileges. This damage manifests as a classic local privilege escalation, enabling total system compromise including data theft, tampering, or service disruption. The CVSS score of 8.8 underscores the severity of the vulnerability, ranking it in the high to critical range for systems that are susceptible.
Affected Systems
Affected products encompass IBM AIX 7.2 and 7.3, with outstanding service packs including AIX 7.3 TL04SP2, TL03SP3, TL02SP5, and AIX 7.2 TL05SP13. IBM PowerVM VIOS 4.1 also suffers from the issue, addressed in Fix Packs VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. All provided SPs/FPs are cumulative and incorporate fixes for earlier vulnerabilities, allowing an administrator to upgrade to the latest security level in a single step.
Risk and Exploitability
The high CVSS score indicates substantial impact if exploited, yet the EPSS score is currently unavailable, meaning the real-world likelihood is not quantified in the public data. The vulnerability remains unlisted in CISA KEV, suggesting no confirmed widespread exploitation yet, but the local nature of the attack vector – requiring an unprivileged user to run a crafted command – could be trivially achievable on a compromised or poorly secured workstation. Prompt patch deployment, reboot or Live Update execution, and adherence to the IBM post-update Postgres15 migration instructions are the only means to mitigate it.
OpenCVE Enrichment