IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
The nimsh service (NIM Service Handler) in IBM AIX 7.2 and 7.3 systems implements communication protection through SSL/TLS, however the process control mechanisms are improperly configured or implemented (CWE-114). This flaw allows a remote attacker to bypass security measures and inject and execute arbitrary commands in the service context. The attack requires user interaction, however it is possible to carry out over the network without requiring privileges on the target system.
An attacker can execute arbitrary commands on the vulnerable system, potentially leading to complete host takeover, violation of data confidentiality and integrity, and system destabilization.
Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7186621
IBM AIX 7.2 and IBM AIX 7.3 with the nimsh service running
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HIBM Aix
OSIbm7.27.3
Related vulnerabilities
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due t...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...