PT-2025-46923 · Ibm · Aix+2

CVE-2025-36250

·

Publicado

2025-11-13

·

Atualizado

2025-12-23

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM AIX versions 7.2 and 7.3 IBM VIOS versions 3.1 and 4.1
Description The NIM server (formerly known as NIM master) service (nimesis) in IBM AIX and IBM VIOS may allow a remote attacker to execute arbitrary commands and traverse directories on the system. An attacker could potentially send a specially crafted URL request to write arbitrary files. This issue addresses additional attack vectors for a previously addressed issue.
Recommendations IBM AIX version 7.2 IBM AIX version 7.3 IBM VIOS version 3.1 IBM VIOS version 4.1 Restrict access to the NIM server.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14676
CVE-2025-36250

Produtos afetados

Aix
Ibm Aix
Vios