IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
The SSL/TLS implementation in the nimsh service (Network Installation Management Service Host) contains improper process control mechanisms (CWE-114 — Process Control). An attacker can send a specially crafted network request that exploits this vulnerability to execute arbitrary system commands in the context of the service. The vulnerability is accessible remotely over the network, without requiring privileges on the attacked system, with minimal user interaction.
An attacker can remotely execute arbitrary commands on the vulnerable system, leading to complete system takeover, disclosure of confidential data, or violation of system integrity.
Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7251173
IBM AIX 7.2, IBM AIX 7.3, IBM VIOS 3.1, IBM VIOS 4.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:LIBM Aix
OSIbm7.27.3IBM Vios
APPIbm3.1.04.1.0
Related vulnerabilities
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due t...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a...