8.2
CVE-2026-18840
- EPSS -
- Veröffentlicht 20.08.2026 22:17:17
- Zuletzt bearbeitet 20.08.2026 22:17:17
- CVE-Watchlists
- Unerledigt
Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
AIX
Version
7.2
Status
affected
Version
7.3
Status
affected
HerstellerIBM
≫
Produkt
PowerVM VIOS
Version
4.1
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
https://www.ibm.com/support/pages/node/7283858