Impact
IBM i 7.4, 7.5, 7.6 and 7.3 permit a remote attacker to send a specially crafted TLS handshake that forces the server to downgrade the TLS protocol to a version that the server configuration has disabled. This flaw weakens encryption and can lead to confidentiality compromise or provide a foothold for further attacks that rely on reduced security. The weakness is classified as CWE-757, an algorithm downgrade vulnerability.
Affected Systems
Affects IBM i releases 7.3, 7.4, 7.5, and 7.6. The official remedy is IBM i Release5770-SS1, which incorporates the relevant PTFs for each release. Users running older or unsupported IBM i versions should plan to upgrade to a supported, patched release.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can trigger the downgrade by sending a crafted TLS handshake over the network; no authentication or local privileges are required, so the attack is remote and network‑based. This increases the attack surface for potential confidentiality or integrity violations, depending on how the downgraded protocol is used by clients and services.
OpenCVE Enrichment