Unrated severityNVD Advisory· Published Jul 22, 2021· Updated Aug 3, 2024
Akkadian Provisioning Manager Engine (PME) Shell Escape via 'exec' command
CVE-2021-31580
Description
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from shell to exec and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).
Affected products
1- Range: 4.50.18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.