PT-2023-2525 · Ibm · Vios+1

Tim Brown

·

Published

2023-04-12

·

Updated

2023-05-12

·

CVE-2023-26286

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM AIX versions 7.1 through 7.3 VIOS version 3.1
Description The issue allows a non-privileged local user to exploit a vulnerability in the AIX runtime services library, specifically due to the lack of neutralization of special elements used in the operating system command, to execute arbitrary commands. This is related to the errlog() system call function in the runtime services library of the IBM AIX operating system.
Recommendations For IBM AIX versions 7.1 through 7.3, consider disabling the errlog() function as a temporary workaround until a patch is available. For VIOS version 3.1, consider restricting access to the runtime services library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-02324
CVE-2023-26286

Affected Products

Ibm Aix
Vios