CVE-2024-56347
published 2025-03-18CVE-2024-56347: IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
PriorityP359critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.86%
54.2th percentile
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | vios | — | — |
| ibm | vios | — | — |
| ibm | vios | — | — |
| ibm | vios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hfx3-278h-qhxq: IBM AIX 7
ghsa_unreviewed·2025-11-14·CVSS 9.6
CVE-2025-36251 [CRITICAL] CWE-114 GHSA-hfx3-278h-qhxq: IBM AIX 7
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
GHSA
GHSA-67g9-m5c8-562g: IBM AIX 7
ghsa_unreviewed·2025-03-18
CVE-2024-56347 [CRITICAL] CWE-114 GHSA-67g9-m5c8-562g: IBM AIX 7
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-18
Published