216.73.217.22

CVE-2025-36251

· Published 13/11/2025 22:15 · Modified 19/11/2025 22:08

Labels: CVE-2025-36251 2025-11-13CVE-2025-36251CWE-114[email protected]

Essential information

Published
13/11/2025 22:15
Modified
19/11/2025 22:08
Author
Creator
CVSS
9.6 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

CVSS metrics

Description

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / vios cpe:2.3:a:ibm:vios:3.1.0:*:*:*:*:*:*:*
ibm / vios cpe:2.3:a:ibm:vios:4.1.0:*:*:*:*:*:*:*
ibm / aix cpe:2.3:o:ibm:aix:7.2:*:*:*:*:*:*:*
ibm / aix cpe:2.3:o:ibm:aix:7.3:*:*:*:*:*:*:*

References