IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
| Software | From | Fixed in |
|---|---|---|
| ibm / vios | 3.1.0 | 3.1.0.x |
| ibm / vios | 4.1.0 | 4.1.0.x |
| ibm / aix | 7.2 | 7.2.x |
| ibm / aix | 7.3 | 7.3.x |