Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-3187Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM AIX

Severity
10.0CRITICALNVD
EPSS
79.5%
top 0.91%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedAug 30
Latest updateMay 14

Description

Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDibm/aix5.3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4725-mf58-37j2: Buffer overflow in ftpd in IBM AIX 52022-05-14
CVEList
CVE-2010-3187: Buffer overflow in ftpd in IBM AIX 52010-08-30

💥Exploits & PoCs

2
Exploit-DB
IBM AIX 5l - 'FTPd' Remote DES Hash2010-07-24
Exploit-DB
AIX5l with FTP-Server - Hash Disclosure2010-07-18
CVE-2010-3187 — IBM AIX vulnerability | cvebase