CRITICAL🇵🇱 Wersja polska

CVE-2024-56347

CVSS 9.6v3.1pub. 2025-03-18upd. 2025-07-25

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

🤖 AI Analysis
How it works

The nimsh service (NIM Service Handler) in IBM AIX 7.2 and 7.3 systems implements communication protection through SSL/TLS, however the process control mechanisms are improperly configured or implemented (CWE-114). This flaw allows a remote attacker to bypass security measures and inject and execute arbitrary commands in the service context. The attack requires user interaction, however it is possible to carry out over the network without requiring privileges on the target system.

Impact

An attacker can execute arbitrary commands on the vulnerable system, potentially leading to complete host takeover, violation of data confidentiality and integrity, and system destabilization.

Mitigation & patch

Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7186621

Who is affected

IBM AIX 7.2 and IBM AIX 7.3 with the nimsh service running

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • IBM Aix

    OS
    Ibm
    7.27.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-17118CRITICAL9.8same product

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...

CVE-2026-17122CRITICAL9.8same product

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...

CVE-2026-16926CRITICAL9.1same product

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due t...

CVE-2026-17040CRITICAL9.8same product

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...

CVE-2026-17136CRITICAL9.8same product

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...