First published: Fri Mar 04 2022(Updated: )
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | <=7.1 | |
IBM AIX | <=7.2 | |
IBM AIX | <=7.3 | |
IBM Virtual I/O Server (VIOS) | <=3.1 | |
IBM Virtual I/O Server (VIOS) | >=3.1.1<3.1.1.60 | |
IBM Virtual I/O Server (VIOS) | >=3.1.2<3.1.2.40 | |
IBM Virtual I/O Server (VIOS) | >=3.1.3<3.1.3.20 | |
IBM AIX | >=7.1.5.0<=7.1.5.37 | |
IBM AIX | >=7.2.4.0<=7.2.4.4 | |
IBM AIX | =7.2.5.0 | |
IBM AIX | =7.2.5.1 | |
IBM AIX | =7.2.5.100 | |
IBM AIX | =7.3.0-sp1 | |
IBM AIX | =7.3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22351 is a vulnerability in IBM AIX and VIOS that allows a non-privileged trusted host user to cause a denial of service in the nimsh daemon on another trusted host.
IBM AIX versions 7.1, 7.2, and 7.3, as well as VIOS versions 3.1.1 to 3.1.3 are affected by CVE-2022-22351.
CVE-2022-22351 has a severity rating of 8.6, which is considered high.
A non-privileged trusted host user can exploit CVE-2022-22351 by exploiting a vulnerability in the nimsh daemon.
Yes, IBM has provided a fix for CVE-2022-22351. Please refer to the IBM Support page for more information on how to apply the fix.