{"id":"CVE-2021-38647","title":"Open Management Infrastructure (OMI) Remote Code Execution Vulnerability","summary":"Open Management Infrastructure (OMI) Remote Code Execution Vulnerability","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"microsoft","product":"azure_automation_state_configuration","affected":["azure_automation_state_configuration","azure_automation_update_management","azure_diagnostics_(lad)","azure_security_center","azure_sentinel","azure_stack_hub","container_monitoring_solution","log_analytics_agent","open_management_infrastructure < 1.6.8-1","system_center_operations_manager"],"patched":["open_management_infrastructure 1.6.8-1"],"published":"2021-09-15","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-38647","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647","label":"secure@microsoft.com"},{"url":"http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38647","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99933,"epssPercentile":0.9997,"kev":true,"kevDateAdded":"2021-11-03","kevDueDate":"2021-11-17","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-11T16:47:01.328Z","exploits":{"github":12,"githubRepos":["https://github.com/corelight/CVE-2021-38647","https://github.com/midoxnet/CVE-2021-38647","https://github.com/horizon3ai/CVE-2021-38647"],"metasploit":["exploit/linux/misc/cve_2021_38647_omigod"],"nuclei":["CVE-2021-38647"],"checkedAt":"2026-09-19T16:22:51.555Z"},"exploitAvailable":true,"slug":"CVE-2021-38647","body":"## Overview\n\nOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability\n\n## Affected\n\n- `azure_automation_state_configuration`\n- `azure_automation_update_management`\n- `azure_diagnostics_(lad)`\n- `azure_security_center`\n- `azure_sentinel`\n- `azure_stack_hub`\n- `container_monitoring_solution`\n- `log_analytics_agent`\n- `open_management_infrastructure < 1.6.8-1`\n- `system_center_operations_manager`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `open_management_infrastructure 1.6.8-1`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":20,"exploitation":25,"ransomware":5},"changes":[{"seq":4534,"id":"CVE-2021-38647","ts":1788887189125,"field":"exploit_available","old":"false","new":"true"},{"seq":3417,"id":"CVE-2021-38647","ts":1788886306050,"field":"exploit_available","old":"true","new":"false"},{"seq":2272,"id":"CVE-2021-38647","ts":1788882975516,"field":"exploit_available","old":"false","new":"true"},{"seq":1301,"id":"CVE-2021-38647","ts":1788882387348,"field":"exploit_available","old":"true","new":"false"},{"seq":415,"id":"CVE-2021-38647","ts":1788881823290,"field":"exploit_available","old":"false","new":"true"}]}