Vios
Vendor:
First CVE: Oct 15, 2009 · Active for 16 years
92
Total CVEs
More Total CVEs than 99% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vios over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 15, 2009
16 years ago
Most Recent CVE
Apr 23, 2026
93 days ago
CVE Severity & Scoring
Vios92 CVEs
47%
42%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local60 (65.2%)
Network11 (12.0%)
Unknown21 (22.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (68.5%)
High8 (8.7%)
Unknown21 (22.8%)
User Interaction
None70 (76.1%)
Unknown21 (22.8%)
Required1 (1.1%)
Privileges Required
Low43 (46.7%)
High3 (3.3%)
None25 (27.2%)
Unknown21 (22.8%)
Top CVEs
Signals from CVEs in this product scope (92 CVEs).
92 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3699HIGH Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to | Oct 15, 2009 | 10.0 | 79 | NO | YES |
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear | Oct 15, 2014 | 3.4 | 78 | NO | YES |
CVE-2010-1039HIGH Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B | May 20, 2010 | 10.0 | 53 | NO | YES |
CVE-2016-8972HIGH IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV910 | Feb 15, 2017 | 7.8 | 36 | NO | YES |
CVE-2013-4011HIGH Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1 | Jul 18, 2013 | 7.2 | 36 | NO | YES |
CVE-2025-36251CRITICAL IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. T | Nov 13, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-36250CRITICAL IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improp | Nov 13, 2025 | 9.8 | 35 | NO | NO |
CVE-2016-6079HIGH IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV8 | Feb 15, 2017 | 7.8 | 35 | NO | YES |
CVE-2023-28528HIGH IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 2512 | Apr 28, 2023 | 7.8 | 34 | NO | YES |
CVE-2025-36236CRITICAL IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An a | Nov 13, 2025 | 9.1 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (92 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
4.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
7.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (92 CVEs).
Media Mentions
Signals from CVEs in this product scope (92 CVEs).
Top CNAs Publishing CVEs For Vios
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.2.0 | 7 | 5.4 | 0.4% | 0 | 0 |
| 4.1.1 | 1 | 8.4 | 0.2% | 0 | 0 |
| 4.1.0 | 4 | 9.2 | 0.5% | 0 | 0 |
| 4.1 | 8 | 6.8 | 0.2% | 0 | 0 |
| 3.1.2 | 1 | 4.7 | 0.4% | 0 | 0 |
| 3.1.1 | 1 | 4.7 | 0.4% | 0 | 0 |
| 3.1.0 | 7 | 7.7 | 0.4% | 0 | 0 |
| 3.1 | 46 | 6.5 | 0.3% | 0 | 1 |
| 2.2.5.10 | 2 | 7.8 | 1.9% | 0 | 2 |
| 2.2.5.0 | 2 | 7.8 | 1.9% | 0 | 2 |
| 2.2.4.30 | 2 | 7.8 | 1.9% | 0 | 2 |
| 2.2.4.23 | 2 | 7.8 | 1.9% | 0 | 2 |
| 2.2.4.22 | 3 | 6.4 | 1.8% | 0 | 2 |
| 2.2.4.21 | 3 | 6.4 | 1.8% | 0 | 2 |
| 2.2.4.10 | 3 | 6.4 | 1.8% | 0 | 2 |
| 2.2.4.0 | 3 | 6.4 | 1.8% | 0 | 2 |
| 2.2.3.80 | 2 | 7.8 | 1.9% | 0 | 2 |
| 2.2.3.70 | 3 | 6.4 | 1.8% | 0 | 2 |
| 2.2.3.60 | 3 | 6.4 | 1.8% | 0 | 2 |
| 2.2.3.52 | 3 | 6.4 | 1.8% | 0 | 2 |