📦 Vios

by Ibm

🔍 What is Vios?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-36251

CRITICAL CVSS 9.6 Nov 13, 2025

This vulnerability in IBM AIX and VIOS nimsh service allows remote attackers to execute arbitrary commands due to improper SSL/TLS process controls. It affects IBM AIX 7.2, 7.3 and IBM VIOS 3.1, 4.1 s...

CVE-2025-36250

CRITICAL CVSS 10.0 Nov 13, 2025

This vulnerability allows remote attackers to execute arbitrary commands on IBM AIX and VIOS systems running the NIM server service (nimesis) due to improper process controls. It affects IBM AIX 7.2, ...

CVE-2025-36096

CRITICAL CVSS 9.0 Nov 13, 2025

IBM AIX and VIOS systems store NIM private keys insecurely, allowing attackers with network access to intercept and misuse these keys. This affects IBM AIX 7.2-7.3 and VIOS 3.1-4.1 systems using NIM e...

CVE-2025-36244

HIGH CVSS 7.4 Sep 16, 2025

This vulnerability allows local users on affected IBM AIX and VIOS systems to write files with root privileges when Kerberos authentication is configured. The issue stems from improper initialization ...

CVE-2025-33112

HIGH CVSS 8.4 Jun 10, 2025

This vulnerability in IBM AIX and VIOS Perl implementations allows a local non-privileged user to execute arbitrary code by exploiting improper pathname input sanitization. The flaw enables privilege ...

CVE-2024-47115

HIGH CVSS 7.8 Dec 7, 2024

This CVE describes a local privilege escalation vulnerability in IBM AIX and VIOS systems where improper input sanitization allows a local user to execute arbitrary commands with elevated privileges. ...

CVE-2024-27260

HIGH CVSS 8.4 May 16, 2024

This vulnerability allows a non-privileged local user on affected IBM AIX and VIOS systems to exploit a flaw in the invscout command to execute arbitrary commands with elevated privileges. This is a l...

CVE-2024-25021

HIGH CVSS 8.4 Feb 22, 2024

This vulnerability in IBM AIX 7.3 and VIOS 4.1's Perl implementation allows a non-privileged local user to execute arbitrary commands with elevated privileges. It affects systems running these specifi...

CVE-2023-45174

HIGH CVSS 8.4 Dec 13, 2023

A local privilege escalation vulnerability in IBM AIX and VIOS allows privileged local users to exploit the qdaemon command to gain elevated privileges or cause denial of service. This affects IBM AIX...

CVE-2023-45166

HIGH CVSS 8.4 Dec 13, 2023

A local privilege escalation vulnerability in IBM AIX and VIOS allows non-privileged local users to exploit the piodmgrsu command to gain elevated privileges. This affects IBM AIX 7.2, 7.3, and VIOS 3...

CVE-2023-45168

HIGH CVSS 8.4 Dec 1, 2023

This vulnerability allows a non-privileged local user on IBM AIX and VIOS systems to exploit the invscout command to execute arbitrary commands with elevated privileges. It affects IBM AIX 7.2, 7.3, a...

CVE-2023-26286

HIGH CVSS 8.4 Apr 26, 2023

This vulnerability allows a non-privileged local user on IBM AIX and VIOS systems to execute arbitrary commands with elevated privileges by exploiting a flaw in the AIX runtime services library. It af...

CVE-2022-22351

HIGH CVSS 8.6 Mar 7, 2022

This vulnerability in IBM AIX and VIOS allows a non-privileged user on a trusted host to exploit the nimsh daemon to cause denial of service on another trusted host. It affects IBM AIX 7.1, 7.2, 7.3 a...

CVE-2021-38991

HIGH CVSS 7.8 Jan 11, 2022

This vulnerability allows a non-privileged local user on affected IBM AIX and VIOS systems to exploit a flaw in the lscore command, potentially leading to arbitrary code execution with elevated privil...

CVE-2021-29741

HIGH CVSS 7.8 Aug 2, 2021

This vulnerability in IBM AIX and VIOS allows a local user to exploit a flaw in Korn Shell (ksh) to escalate privileges to root. It affects IBM AIX 7.1, 7.2, and VIOS 3.1 systems. Attackers must have ...

CVE-2024-52906

MEDIUM CVSS 5.5 Dec 25, 2024

A local privilege escalation vulnerability in IBM AIX and VIOS TCP/IP kernel extension allows non-privileged local users to cause a denial of service. This affects IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 ...

CVE-2024-47102

MEDIUM CVSS 5.5 Dec 25, 2024

A local privilege escalation vulnerability in IBM AIX's perfstat kernel extension allows non-privileged local users to cause a denial of service. This affects IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 syste...