Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-1329IBM AIX vulnerability

7 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.6%
top 31.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedDec 20
Latest updateMay 1

Description

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDibm/aix8 versions+7

Patches

🔴Vulnerability Details

4
GHSA
GHSA-6gph-f755-prg4: The lsmcode program on IBM AIX 52022-05-01
GHSA
GHSA-62v7-vwcm-484q: Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 52022-04-29
CVEList
CVE-2008-1600: The lsmcode program on IBM AIX 52008-03-31
CVEList
CVE-2004-1329: Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 52005-01-06

💥Exploits & PoCs

1
Exploit-DB
IBM AIX 5.x - 'Diag' Local Privilege Escalation2004-12-20
CVE-2004-1329 — IBM AIX vulnerability | cvebase