cve/2023/CVE-2023-28528.md

18 lines
858 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-28528](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28528)
![](https://img.shields.io/static/v1?label=Product&message=AIX&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%207.1%2C%207.2%2C%207.3%2C%20VIOS%203.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-78%20Improper%20Neutralization%20of%20Special%20Elements%20used%20in%20an%20OS%20Command%20('OS%20Command%20Injection')&color=brighgreen)
### Description
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.
### POC
#### Reference
- http://packetstormsecurity.com/files/172458/IBM-AIX-7.2-inscout-Privilege-Escalation.html
#### Github
No PoCs found on GitHub currently.