CVE-2025-36250
AIX Code Execution
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. Β This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
| CWE | CWE-114 |
| Vendor | ibm |
| Product | aix |
| Published | Nov 13, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for ibm aix
Be the first to know when new critical vulnerabilities affecting ibm aix are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
IBM / AIX
7.2 7.3
IBM / VIOS
3.1 4.1
References
Credits
These vulnerabilities were reported to IBM by Oneconsult AG (https://oneconsult.com/), Jan Alsenz.