Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2004-1329

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.3%
CVSS Severity
CVSS v2 Score 7.2
References
Products affected by CVE-2004-1329
  • Ibm » Aix » Version: 5.1
    cpe:2.3:o:ibm:aix:5.1
  • Ibm » Aix » Version: 5.1l
    cpe:2.3:o:ibm:aix:5.1l
  • Ibm » Aix » Version: 5.2
    cpe:2.3:o:ibm:aix:5.2
  • Ibm » Aix » Version: 5.2.2
    cpe:2.3:o:ibm:aix:5.2.2
  • Ibm » Aix » Version: 5.2_l
    cpe:2.3:o:ibm:aix:5.2_l
  • Ibm » Aix » Version: 5.3
    cpe:2.3:o:ibm:aix:5.3
  • Ibm » Aix » Version: 5.3_l
    cpe:2.3:o:ibm:aix:5.3_l


Contact Us

Shodan ® - All rights reserved