CVE-2021-38648

CVE Published 2021-09-15
Related CWE(s) CWE-287: Improper Authentication
Related Vendor(s) microsoft
Related Product(s) azure_automation_update_management, azure_automation_state_configuration, log_analytics_agent, azure_stack_hub, azure_open_management_infrastructure, azure_sentinel, system_center_operations_manager, azure_security_center, container_monitoring_solution, azure_diagnostics_\(lad\)
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 7.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Open Management Infrastructure Elevation of Privilege Vulnerability

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References