QID 330153

Date Published: 2023-12-06

QID 330153: IBM AIX Inventory Scout Arbitrary Command Execution Vulnerability (invscout_advisory5)

A vulnerability in the AIX invscout command could allow a non-privileged local user to execute arbitrary commands (CVE-2023-45168).

Affected Versions:-
AIX 7.2 and 7.3

QID Detection logic
It checks for the vulnerable file of invscout.rte using command lslpp -L | grep -i invscout.rte

Successful exploit may allow a non-privileged local user to execute arbitrary commands

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Vendor fixes are available to resolve the issue. Refer to AIX invscout advisory 5 to address this issue and obtain details on the fixes.

    CVEs related to QID 330153

    Software Advisories
    Advisory ID Software Component Link
    invscout_advisory5 URL Logo aix.software.ibm.com/aix/efixes/security/invscout_advisory5.asc