CVE-2025-36250: AIX Code Execution
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36250?
CVE-2025-36250 is considered a high severity vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2025-36250?
To mitigate CVE-2025-36250, you should apply the latest security patches provided by IBM for AIX and VIOS.
What versions are affected by CVE-2025-36250?
CVE-2025-36250 affects IBM AIX versions 7.2 and 7.3, as well as IBM VIOS versions 3.1 and 4.1.
What type of attacks are associated with CVE-2025-36250?
CVE-2025-36250 allows for remote command execution attacks due to improper process controls.
Is CVE-2025-36250 a new vulnerability?
CVE-2025-36250 addresses additional attack vectors for a previously known vulnerability, indicating it is not entirely new.