Vios IBM Vios

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Vios.

By the Year

In 2026 there have been 0 vulnerabilities in IBM Vios. Last year, in 2025 Vios had 6 security vulnerabilities published. Right now, Vios is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 6 8.77
2024 10 6.08
2023 10 7.17
2022 23 6.28
2021 8 6.11
2020 1 7.80

It may take a day or so for new Vios vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Vios Security Vulnerabilities

IBM AIX 7.2/7.3 NIM Service Directory Traversal Remote File Write
CVE-2025-36236 8.2 - High - November 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.

Directory traversal

IBM NIM Server (nimesis) RCE via Improper ProcCtrl AIX 7.2/7.3 VIOS 3.1/4.1
CVE-2025-36250 10 - Critical - November 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls.  This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.

Process Control

IBM AIX/VIOS 7.2/7.3,3.1/4.1 NIM Key Storage Flaw
CVE-2025-36096 9 - Critical - November 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.

Insufficiently Protected Credentials

Exec via Process Control Flaw in IBM AIX+VIOS nimsh SSL/TLS (7.2/7.3,3.1/4.1)
CVE-2025-36251 9.6 - Critical - November 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.

Process Control

IBM AIX 7.2/7.3 + VIOS 3.1/4.1 Kerberos Init Elevates Privileges
CVE-2025-36244 7.4 - High - September 16, 2025

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.

External Initialization of Trusted Variables or Data Stores

IBM AIX 7.3, VIOS 4.1.1: Arbitrary Code Exec via Perl Pathname Issue
CVE-2025-33112 8.4 - High - June 10, 2025

IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.

Relative Path Traversal

IBM AIX TCP/IP Kernel Extension Denial of Service Vulnerability
CVE-2024-52906 5.5 - Medium - December 25, 2024

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.

Race Condition

IBM AIX perfstat Kernel Extension Denial of Service Vulnerability
CVE-2024-47102 5.5 - Medium - December 25, 2024

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.

AuthZ

IBM AIX and VIOS Local Command Execution Vulnerability
CVE-2024-47115 7.8 - High - December 07, 2024

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

Shell injection

Local Priv Escalation in IBM AIX invscout (7.3, VIOS 4.1)
CVE-2024-27260 - May 16, 2024

IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.

Execution with Unnecessary Privileges

Privilege Escalation via UNIX DGRAM Socket in IBM AIX 7.2/7.3 & VIOS 3.1/4.1
CVE-2024-27273 7.8 - High - May 07, 2024

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.

IBM AIX 7.3 VIOS 4.1 Local Exec via Perl Vulnerability
CVE-2024-25021 - February 22, 2024

IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.

IBM AIX 7.2/7.3 & VIOS 3.1 pmsvcs KEXT Local Non-Priv DOS
CVE-2023-45169 5.5 - Medium - January 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967.

IBM AIX 7.x/VIOS 3.1 kernel DoS by local non-privileged user (CVE-2023-45171)
CVE-2023-45171 5.5 - Medium - January 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-Force ID: 267969.

AIX 7.x NFS KERNEL EXT DoS via local exploit
CVE-2023-45173 5.5 - Medium - January 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service. IBM X-Force ID: 267971.

DoS in IBM AIX 7.2/7.3/VIOS 3.1 TCP/IP Kernel Extension
CVE-2023-45175 5.5 - Medium - January 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 267973.

IBM AIX 7.2/7.3 & VIOS 3.1 Local DoS via AIX Windows
CVE-2023-45172 5.5 - Medium - December 19, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X-Force ID: 267970.

Priv Esc via piodmgrsu in IBM AIX 7.2/7.3 & VIOS 3.1
CVE-2023-45166 7.8 - High - December 13, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.

IBM AIX 7.2/7.3 & VIOS 3.1 local privilege escalation via qdaemon
CVE-2023-45174 7.8 - High - December 13, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.

IBM AIX 7.2/7.3 piobe cmd local privilege escalation
CVE-2023-45170 7.8 - High - December 13, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.

IBM AIX/VIOS invscout Local Cmd Exec 7.2-7.3, 3.1 (CVE-2023-45168)
CVE-2023-45168 7.8 - High - December 01, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 267966.

IBM AIX 7.3 Python Denial of Service via Local User
CVE-2023-45167 5.5 - Medium - November 10, 2023

IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965.

IBM AIX 7.2/7.3 viOS 3.1 OpenSSH Improper Access Control
CVE-2023-40371 5.5 - Medium - August 24, 2023

IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force ID: 263476.

Use of a Broken or Risky Cryptographic Algorithm

Non-Priv Local Command Execution via invscout in IBM AIX 7.17.3 & VIOS 3.1
CVE-2023-28528 8.4 - High - April 28, 2023

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.

Shell injection

AIX Runtime Services Lib Local Cmd Exec on AIX 7.17.3 & VIOS 3.1
CVE-2023-26286 7.8 - High - April 26, 2023

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.

IBM AIX 7.1-7.3 X11 Buffer Overflow CVE-2022-47990
CVE-2022-47990 7.8 - High - January 18, 2023

IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could result in a denial of service or arbitrary code execution. IBM X-Force ID: 243556.

Classic Buffer Overflow

IBM AIX Kernel DoS in 7.1-7.3 & VIOS 3.1 (CVE-2022-39164)
CVE-2022-39164 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

IBM AIX 7.17.3/VIOS 3.1 pfcdd Kernel DoS
CVE-2022-43849 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a denial of service. IBM X-Force ID: 239170.

Denial of Service via perfstat kernel extension in IBM AIX 7.17.3 & VIOS 3.1
CVE-2022-43848 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service. IBM X-Force ID: 239169.

IBM AIX 7.1/7.2/7.3 & VIOS 3.1 Privilege Escalation via rm_rlcache_file
CVE-2022-41290 8.4 - High - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.

Improper Privilege Management

Non-Privileged Local User Exploit in CAA Causing DoS on IBM AIX 7.1-7.3 & VIOS 3.1
CVE-2022-39165 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183.

IBM AIX 7.[1-3]/VIOS 3.1 TCP/IP KEXT local DoS (CVE202240233)
CVE-2022-40233 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 235599.

Local DoS via NFS kernel extension in IBM AIX 7.1-7.3, VIOS 3.1
CVE-2022-43380 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS kernel extension to cause a denial of service. IBM X-Force ID: 238640.

IBM AIX SMB client DoS (pre-7.3, VIOS 3.1)
CVE-2022-43381 6.2 - Medium - December 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-Force ID: 238639.

IBM AIX lpd Daemon DoS (v7.1-7.3, VIOS3.1)
CVE-2022-43382 4.4 - Medium - December 20, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.

IBM AIX 7.17.3 & VIOS 3.1 Kernel LPE via Local User
CVE-2022-34356 7.8 - High - September 13, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.

IBM AIX invscout Root Escalation (before 7.4)
CVE-2022-36768 7.8 - High - September 13, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service
CVE-2022-22444 5.5 - Medium - June 15, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 224444.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38988 5.5 - Medium - March 07, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38989 5.5 - Medium - March 07, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2022-22351 8.6 - High - March 07, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38996 5.5 - Medium - March 02, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service
CVE-2022-22350 5.5 - Medium - March 02, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38955 4.4 - Medium - March 01, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38993 5.5 - Medium - February 25, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service. IBM X-Force ID: 212962.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38995 5.5 - Medium - February 24, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213073.

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could
CVE-2021-38994 5.5 - Medium - February 24, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213072.

IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could
CVE-2021-38991 7.8 - High - January 11, 2022

IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.

IBM AIX 7.1, 7.2, and VIOS 3.1 could
CVE-2021-38990 7.8 - High - January 10, 2022

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information
CVE-2021-29861 6.2 - Medium - November 17, 2021

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force ID: 206085.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Vios or by IBM? Click the Watch button to subscribe.

IBM
Vendor

IBM Vios
Product

subscribe