Lucene search

K
vulnrichmentIbmVULNRICHMENT:CVE-2023-26286
HistoryApr 26, 2023 - 11:50 a.m.

CVE-2023-26286 IBM AIX privilege escalation

2023-04-2611:50:34
ibm
github.com
4
ibm
aix
privilege escalation
cve-2023-26286
x-force id
vulnerability
arbitrary commands
local user
runtime services
vios 3.1

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.

CNA Affected

[
  {
    "vendor": "IBM",
    "product": "AIX",
    "versions": [
      {
        "status": "affected",
        "version": "7.1, 7.2, 7.3, VIOS 3.1"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-26286