CVE-2023-28528: IBM AIX command execution
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.
Other sources
IBM AIX could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this IBM AIX vulnerability?
The vulnerability ID for this IBM AIX vulnerability is CVE-2023-28528.
What is the severity of CVE-2023-28528?
CVE-2023-28528 has a severity rating of 8.4, which is considered high.
What software versions are affected by CVE-2023-28528?
IBM AIX 7.1, 7.2, 7.3, and IBM VIOS 3.1 are affected by this vulnerability.
How can a non-privileged local user exploit this vulnerability?
A non-privileged local user can exploit this vulnerability by using the invscout command to execute arbitrary commands.
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the following IBM support page for more information: [IBM Support Page](https://www.ibm.com/support/pages/node/6983232)