PT-2023-8369 · Ibm · Vios+1

Published

2023-12-12

·

Updated

2023-12-19

·

CVE-2023-45166

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM AIX versions 7.2 through 7.3 VIOS version 3.1
Description The issue is related to insufficient input validation, which can be exploited by a non-privileged local user to obtain elevated privileges using the piodmgrsu command. This can lead to privilege escalation.
Recommendations For IBM AIX versions 7.2 through 7.3, consider disabling the piodmgrsu command until a patch is available to prevent exploitation. For VIOS version 3.1, restrict access to the piodmgrsu command to minimize the risk of exploitation. Note: The piobe command mentioned in another source is not confirmed as vulnerable in the higher-priority sources, so no recommendation is provided for it. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00565
CVE-2023-45166

Affected Products

Ibm Aix
Vios