CVE-2025-36096: AIX Insufficiently Protected Credentials
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36096?
CVE-2025-36096 has been classified as a high severity vulnerability due to its potential for unauthorized access to sensitive private keys.
How do I fix CVE-2025-36096?
To fix CVE-2025-36096, ensure that NIM private keys are stored securely and apply any relevant security updates provided by IBM.
Which versions of software are affected by CVE-2025-36096?
CVE-2025-36096 affects IBM AIX versions 7.2 and 7.3, as well as IBM VIOS versions 3.1 and 4.1.
What are the potential risks associated with CVE-2025-36096?
The potential risks of CVE-2025-36096 include unauthorized access to NIM environments and possible man-in-the-middle attacks.
Is there a public exploit available for CVE-2025-36096?
As of now, there has been no public exploit released for CVE-2025-36096, but it is advisable to remediate this vulnerability promptly.