CVE-2020-4829: High severity IBM AIX vulnerability
Published Dec 8, 2020
·Updated
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.
Other sources
IBM AIX could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges.
— IBM
Affected Software
6 affected components
IBM AIX<=7.1
IBM AIX<=7.2
IBM VIOS<=3.1
IBM VIOS=3.1
IBM AIX=7.1
IBM AIX=7.2
Remediation
Patch Available
Event History
Dec 8, 2020
CVE Published
via IBM·12:00 AM
Dec 9, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-4829?
CVE-2020-4829 is a vulnerability in IBM AIX and VIOS that could allow a local user to gain root privileges.
2
What are the affected versions of IBM AIX and VIOS?
IBM AIX versions 7.1 and 7.2, as well as IBM VIOS version 3.1, are affected by CVE-2020-4829.
3
What is the severity of CVE-2020-4829?
The severity of CVE-2020-4829 is rated as high with a CVSS score of 8.4.
4
How can a local user exploit CVE-2020-4829?
A local user can exploit CVE-2020-4829 by using the ksu user command to gain root privileges.
5
Is there any additional information available about CVE-2020-4829?
Yes, you can find more information about CVE-2020-4829 on the IBM X-Force ID page and the IBM support page.