LiveActive security incident?Get immediate response
CVE Record

CVE-2021-29862: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AI...

IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 206086.

MediumCVSS 6.2Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-29862 is a local denial-of-service issue in IBM AIX and VIOS. A local user could trigger a kernel vulnerability and disrupt system availability. It is not described as allowing data theft or code execution, but downtime on AIX or VIOS hosts can affect critical enterprise workloads.

Executive priority

Treat as a moderate availability risk. Prioritize remediation for production AIX and VIOS systems where downtime would disrupt business operations, especially shared infrastructure supporting multiple workloads.

Technical view

IBM reports that AIX 7.1, AIX 7.2, and VIOS 3.1 are affected by a kernel vulnerability. The CVSS v3.0 vector is local, low complexity, no user interaction, high availability impact, and no confidentiality or integrity impact. The source data lists remediation level as official fix available.

Likely exposure

Exposure is limited to organizations running IBM AIX 7.1, AIX 7.2, or VIOS 3.1 where a local user can access the system. This is not presented as a remote internet-facing vulnerability.

Exploitation context

The CVE is not listed as CISA KEV. The provided CVSS vector marks exploit maturity as unproven. Sources support local denial of service only, not remote exploitation, privilege escalation, or data compromise.

Researcher notes

The evidence supports a local kernel denial-of-service condition. The bundle does not provide technical root cause details, exploit procedures, or specific fix identifiers. Avoid assuming broader impact beyond availability disruption on the listed IBM products and versions.

Mitigation direction

  • Review IBM advisory 6483875 for the vendor-supported fix path.
  • Apply IBM-provided fixes for affected AIX and VIOS versions.
  • Restrict unnecessary local user access on affected systems.
  • Prioritize systems supporting critical workloads or virtualization infrastructure.

Validation and detection

  • Inventory AIX 7.1, AIX 7.2, and VIOS 3.1 systems.
  • Compare installed maintenance levels against IBM advisory guidance.
  • Confirm vendor fixes are installed on affected hosts.
  • Review outage records for unexplained kernel crashes or reboots.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-29862 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.2 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/S:U/A:H/PR:N/AV:L/UI:N/I:N/AC:L/C:N/RL:O/E:U/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.2CVSS 3.0MediumCVSS:3.0/S:U/A:H/PR:N/AV:L/UI:N/I:N/AC:L/C:N/RL:O/E:U/RC:C2.53.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

6.2Medium
CVSS 3.0 vector shape for CVE-2021-29862Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/S:U/A:H/PR:N/AV:L/UI:N/I:N/AC:L/C:N/RL:O/E:U/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMVIOS3.1Listed
IBMAIX7.1, 7.2Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.