CVE-2022-36768: High severity IBM VIOS vulnerability
Published Sep 8, 2022
·Updated
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.
Other sources
IBM AIX could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges.
Affected Software
8 affected components
IBM VIOS=3.1
IBM AIX=7.1
IBM AIX=7.2
IBM AIX=7.3
IBM AIX<=7.1
IBM AIX<=7.2
IBM AIX<=7.3
IBM VIOS<=3.1
Remediation
Patch Available
Event History
Sep 8, 2022
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Sep 13, 2022
CVE Published
via MITRE·08:45 PM
Data Sourced
via MITRE·08:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-36768?
CVE-2022-36768 is a vulnerability in IBM AIX and VIOS that could allow a non-privileged local user to obtain root privileges.
2
Which versions of IBM AIX and VIOS are affected by CVE-2022-36768?
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 are affected by CVE-2022-36768.
3
What is the severity rating of CVE-2022-36768?
CVE-2022-36768 has a severity rating of 8.4 (high).
4
How can a non-privileged local user exploit CVE-2022-36768?
A non-privileged local user can exploit CVE-2022-36768 by using the invscout command to gain root privileges.
5
Where can I find more information about CVE-2022-36768?
You can find more information about CVE-2022-36768 at the IBM X-Force ID: 232014.