IBM AIX and VIOS Improper Process Control Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A vulnerability in IBM AIX versions 7.2 and 7.3, as well as IBM VIOS versions 3.1 and 4.1, could enable a remote attacker to execute arbitrary commands. This issue arises from improper process controls in the NIM server (nimesis) service, creating additional attack vectors for a previously addressed vulnerability. The flaw is exploitable when an attacker can establish network connectivity to the affected host.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected system.

Remediation

Users can download the necessary fixes for AIX and VIOS from the IBM AIX efixes security directory. The fixes for NIM server and NIM client are available as interim fix packages, which can be installed using the AIX or VIOS interim fix management tools. Instructions for verifying the integrity of the downloaded fix packages are also provided.

Added: Nov 13, 2025, 10:25 PM
Updated: Nov 13, 2025, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
7.0
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.