← Back to CVE List
CVE-2021-38647NVD
Vulnerability Summary
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Microsoft Azure Automation State Configuration
- Microsoft Azure Automation Update Management
- Microsoft Azure Diagnostics \(lad\)
- Microsoft Azure Security Center
- Microsoft Azure Sentinel
- Microsoft Azure Stack Hub
- Microsoft Container Monitoring Solution
- Microsoft Log Analytics Agent
- Microsoft Open Management Infrastructure < 1.6.8-1
- Microsoft System Center Operations Manager
- Microsoft Open Management Infrastructure 1.6.8-1
External References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647
- http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38647