CVE-2024-56347Process Control in IBM AIX

CWE-114Process Control3 documents3 sources
Severity
9.6CRITICALNVD
EPSS
0.2%
top 63.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18

Description

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages3 packages

CVEListV5ibm/aix7.2, 7.3+1
NVDibm/aix7.2, 7.3+1
CVEListV5ibm/vios3.1, 4.1+1

🔴Vulnerability Details

2
GHSA
GHSA-67g9-m5c8-562g: IBM AIX 72025-03-18
CVEList
IBM AIX command execution2025-03-18
CVE-2024-56347 — Process Control in IBM AIX | cvebase