Critical severity9.8CISA KEVNVD Advisory· Published Sep 15, 2021· Updated Aug 10, 2026
CVE-2021-38647
CVE-2021-38647
Description
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:azure_diagnostics_\(lad\):-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:azure_sentinel:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:azure_stack_hub:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:container_monitoring_solution:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:log_analytics_agent:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:open_management_infrastructure:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:open_management_infrastructure:*:*:*:*:*:*:*:*range: <1.6.8-1
- (no CPE)
- cpe:2.3:a:microsoft:system_center_operations_manager:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647nvdPatchVendor Advisory
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647nvdPatchVendor Advisory
- packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.