← Vulnerability feed

Vulnerability record · CVE-2009-3699 · published 15 October 2009

CVE-2009-3699: IBM AIX and VIOS rpc.cmsd XDR string stack buffer overflow

Ibm · Vios

A stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and VIOS 2.1 and earlier. A remote attacker can send a long XDR string as the first argument to procedure 21 of rpc.cmsd, overflowing a stack buffer and potentially executing arbitrary code. The flaw is remotely reachable over the network with no authentication, making it a serious exposure for unpatched systems running the calendar service.

10.0 CVSS 2.0 High EPSS 62% · top 0.8% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete impact, plus available exploit code and very high EPSS, makes this a critical risk for unpatched AIX and VIOS systems.

What it is

A stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and VIOS 2.1 and earlier. A remote attacker can send a long XDR string as the first argument to procedure 21 of rpc.cmsd, overflowing a stack buffer and potentially executing arbitrary code. The flaw is remotely reachable over the network with no authentication, making it a serious exposure for unpatched systems running the calendar service.

Impact

An attacker can execute arbitrary code with the privileges of the rpc.cmsd process, which typically runs as root on AIX and VIOS. Successful exploitation can lead to full compromise of the affected host.

Attack surface

The vulnerability is reached over the network via RPC calls to procedure 21 of rpc.cmsd, with no authentication or user interaction required per the CVSS vector AV:N/AC:L/Au:N. Any host that can reach the rpc.cmsd service can attempt the attack.

Exploitation

CVE-2009-3699 is not listed in CISA KEV, but EPSS shows a 30-day exploitation probability of 0.62345 (99.1st percentile), and references include an Exploit tag plus a public Immunity tool, indicating exploit code is available.

What to do

  • Apply the IBM AIX and VIOS fixes referenced in the IBM advisories (IZ61628, IZ61717, IZ62123, IZ62237, IZ62569-IZ62572, IZ62672) or the cmsd_advisory.asc efix.
  • If rpc.cmsd is not required, disable or stop the calendar daemon and remove it from inetd or the RPC services configuration.
  • Restrict network access to rpc.cmsd (TCP/UDP port 100068) using firewalls or network segmentation so only trusted hosts can reach it.
  • Monitor IBM security bulletins for updated fixes and re-apply patches if new versions are released.

Detection

  • Monitor network traffic for RPC calls to rpc.cmsd procedure 21 containing unusually long XDR strings.
  • Check AIX and VIOS systems for the presence of rpc.cmsd and confirm whether it is running and exposed.
  • Review system logs and process behavior for crashes or unexpected child processes spawned by rpc.cmsd.
  • Use host-based intrusion detection or endpoint monitoring to alert on abnormal rpc.cmsd activity or memory corruption indicators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc Vendor Advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=825 Patch
http://secunia.com/advisories/36978 Vendor Advisory
http://securitytracker.com/id?1022996
http://www.ibm.com/support/docview.wss?uid=isg1IZ61628
http://www.ibm.com/support/docview.wss?uid=isg1IZ61717
http://www.ibm.com/support/docview.wss?uid=isg1IZ62123
http://www.ibm.com/support/docview.wss?uid=isg1IZ62237
http://www.ibm.com/support/docview.wss?uid=isg1IZ62569
http://www.ibm.com/support/docview.wss?uid=isg1IZ62570
http://www.ibm.com/support/docview.wss?uid=isg1IZ62571
http://www.ibm.com/support/docview.wss?uid=isg1IZ62572 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ62672
http://www.osvdb.org/58726
http://www.securityfocus.com/bid/36615 ExploitPatch
http://www.vupen.com/english/advisories/2009/2846 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53681
https://www.immunityinc.com/downloads/immpartners/aixcmsd10092009.tar.gz
http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc Vendor Advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=825 Patch
http://secunia.com/advisories/36978 Vendor Advisory
http://securitytracker.com/id?1022996
http://www.ibm.com/support/docview.wss?uid=isg1IZ61628
http://www.ibm.com/support/docview.wss?uid=isg1IZ61717
http://www.ibm.com/support/docview.wss?uid=isg1IZ62123
http://www.ibm.com/support/docview.wss?uid=isg1IZ62237
http://www.ibm.com/support/docview.wss?uid=isg1IZ62569
http://www.ibm.com/support/docview.wss?uid=isg1IZ62570
http://www.ibm.com/support/docview.wss?uid=isg1IZ62571
http://www.ibm.com/support/docview.wss?uid=isg1IZ62572 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ62672
http://www.osvdb.org/58726
http://www.securityfocus.com/bid/36615 ExploitPatch
http://www.vupen.com/english/advisories/2009/2846 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53681
https://www.immunityinc.com/downloads/immpartners/aixcmsd10092009.tar.gz

Track CVE-2009-3699 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-56346Ibm aix vulnerabilityIBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.EPSS 1.1%10.0CVE-2010-3187Ibm aix memory buffer overflow vulnerabilityBuffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.EPSS 20%10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2009-3517Ibm aix vulnerabilitynfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass…EPSS 4.4%10.0CVE-2006-5008Ibm aix vulnerabilityUnspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspec…EPSS 3.5%10.0CVE-2005-4272Ibm aix vulnerabilityMultiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.EPSS 9.0%10.0CVE-2005-1037Ibm aix vulnerabilityUnknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.EPSS 2.4%10.0CVE-2004-2388Ibm aix vulnerabilityrexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten b…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2009-3699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.