9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Description
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
AI Analysis
Remote command execution vulnerability in IBM AIX and VIOS due to improper process controls in the nimsh service SSL/TLS implementations
Basic Information
ID
CVE-2025-36251
Source
ibm
Published
Nov 13, 2025 at 22:01
Affected Product
Vendor
IBM
Product
AIX
Version
7.2
Affected Versions
IBM AIX 7.2
IBM AIX 7.3
IBM VIOS 3.1
IBM VIOS 4.1
IBM AIX 7.3
IBM VIOS 3.1
IBM VIOS 4.1
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
IBM
Product
AIX and VIOS
Version
7.2, 7.3, 3.1, 4.1