CVE-2025-36250CWE-114

AIX Code Execution

Critical · published November 13, 2025

CVSS v3.1
10.0
EPSS
1%
Percentile
49.6
In the wild
Unconfirmed
What it is

🚨 An improper process control in IBM AIX 7.2, 7.3, and VIOS 3.1, 4.1 can let attackers execute arbitrary commands remotely — that's like a chef getting access to the locked pantry and changing the entire menu without anyone noticing! 🔥 Think of it like a restaurant kitchen where the head chef has a secret key to the pantry and can change any recipe at will. The lack of proper controls allows an unwanted guest to slip in and whip up their own dish, potentially ruining everything! An attacker could run any command they choose, potentially leading to devastating consequences like data breaches, system failures, or unauthorized access to sensitive information. This is an absolute nightmare scenario for any organization, leaving the door wide open for major disruptions and damages!

Put simply

Think of it like a restaurant kitchen where the head chef has a secret key to the pantry and can change any recipe at will. The lack of proper controls allows an unwanted guest to slip in and whip up their own dish, potentially ruining everything! This vulnerability exists due to improper controls within the NIM server service (nimesis) on IBM AIX and VIOS systems, allowing unauthorized command execution by remote attackers.

What to do

An attacker could run any command they choose, potentially leading to devastating consequences like data breaches, system failures, or unauthorized access to sensitive information. This is an absolute nightmare scenario for any organization, leaving the door wide open for major disruptions and damages! Immediate action is required: apply the latest patches for IBM AIX 7.2, 7.3, and VIOS 3.1, 4.1. Review security configurations and access controls on your NIM server to ensure they are properly set. Stay vigilant and monitor for any unusual activities! You can tackle this! By following these steps, you’ll bolster your defenses and keep your systems secure. 🛡️

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00670 · 49.6th percentile
Weakness
CWE-114 · Process Control
Published
2025-11-13T22:01Z
EPSS history
Timeline
  • 13 NOV 22:01Z
    AIX Code Execution
    cvelistv5