PT-2024-9580 · Ibm · Ibm Aix+1

Published

2024-09-27

·

Updated

2025-01-21

·

CVE-2024-47115

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM AIX versions 7.2 through 7.3 VIOS versions 3.1 through 4.1
Description The issue is related to the improper neutralization of input in the invscout component of IBM AIX and VIOS operating systems, allowing a local user to execute arbitrary commands on the system.
Recommendations For IBM AIX versions 7.2 through 7.3, update to a version that includes the fix for this issue. For VIOS versions 3.1 through 4.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the invscout component until a patch is available.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-11287
CVE-2024-47115

Affected Products

Ibm Aix
Vios