Back

CVE-2004-1329

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

Published: Dec 20, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
ibm aix 5.1
ibm aix 5.1l
ibm aix 5.2
ibm aix 5.2.2
ibm aix 5.2_l
ibm aix 5.3
ibm aix 5.3_l

GitHub Security Advisory GHSA-62v7-vwcm-484q

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3)...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 3.27%

Top 13% most likely to be exploited

Threat Score 29.8 / 100

Data Sources

NVD EPSS GitHub