AIX Snap Vulnerability

HIGH (10.0) No Patch (9801 days)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 7.48% chance of exploitation (percentile: 91%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: Exploit-DB

How we test →

What is it?

The AIX snap command is a utility used to manage system snapshots on IBM's AIX operating system. The vulnerability allows local users to access the shadowed password file by creating a specific directory before the root user runs the snap -a command, potentially leading to unauthorized access.

Am I affected?

You're affected if you use snap command. Affected versions: 4.3.2 If you don't recognise this software, you're probably not affected.

How to fix

No public patch link found in the advisory. Contact the vendor directly for remediation guidance. As immediate mitigation: restrict network access to affected systems if possible.