CVE-2021-38647

CVE Published 2021-09-15
Related CWE(s) CWE-287: Improper Authentication
Related Vendor(s) microsoft
Related Product(s) azure_diagnostics_\(lad\), log_analytics_agent, azure_stack_hub, azure_sentinel, container_monitoring_solution, azure_automation_update_management, azure_automation_state_configuration, azure_security_center, azure_open_management_infrastructure, system_center_operations_manager
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Open Management Infrastructure Remote Code Execution Vulnerability

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References