Remote Command Execution Vulnerability in IBM AIX Nimsh Service
CVE-2024-56347

9.6CRITICAL

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
18 March 2025

Summary

The IBM AIX nimsh service in versions 7.2 and 7.3 has a vulnerability where improper process controls in SSL/TLS protection mechanisms may allow a remote attacker to execute arbitrary commands on the system. This flaw underscores the importance of robust configuration and monitoring to prevent unauthorized access.

Affected Version(s)

AIX 7.2, 7.3

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.