CVE-2025-36251: AIX Command Execution
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36251?
CVE-2025-36251 is classified as a high severity vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2025-36251?
To fix CVE-2025-36251, users should apply the latest security patches provided by IBM for AIX and VIOS.
Which versions are affected by CVE-2025-36251?
CVE-2025-36251 affects IBM AIX versions up to 7.3 and IBM VIOS versions up to 4.1.
What types of attacks can CVE-2025-36251 facilitate?
CVE-2025-36251 can facilitate remote command execution attacks due to improper process controls in SSL/TLS implementations.
Is CVE-2025-36251 a new vulnerability?
CVE-2025-36251 addresses additional attack vectors related to a previously identified vulnerability in CVE-2024-56.