CVE-2023-28528: high-severity vulnerability in IBM AIX
IBM AIX command execution
Published · Updated
36Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.4epss 1.5%
from disclosure to weapon0 days
Published on NVDApr 28
metasploitApr 24
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
IBM · AIXRelated CVEs — IBM AIX
In the same product, most dangerous first.
CVE-2018-1383—CVE-2018-1383EPSS 2.7%CVE-2017-1541—CVE-2017-1541EPSS 1.5%CVE-2026-16850HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 1.5%CVE-2022-22351MEDIUMCVE-2022-22351EPSS 1.2%CVE-2024-56346CRITICALIBM AIX command executionEPSS 1.1%CVE-2026-15068CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 1.1%