S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-31581 Scanner

CVE-2021-31581 scanner - OS Command Injection vulnerability in Akkadian Provisioning Manager Engine (PME)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-31581
4.4
CVSShigh
Requires local system access · requires high privileges.

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

Attack Vector
Local
Privileges Req.
High
User Interaction
None
Affected
Provisioning Manager Engine (PME)by Akkadian
4.50.18
Updated Aug 19, 2026View on NVD →
Detail

Akkadian Provisioning Manager Engine (PME) is a software tool used for automating and managing Cisco Unified Communications and Collaboration (UCC) applications. It is designed to simplify and streamline the process of deploying and managing UCC applications. PME provides a restricted shell that is used for security purposes, which helps to prevent unauthorized access and ensure data privacy. The software is an enterprise solution that enables IT departments to manage their UCC applications easily and efficiently.

The CVE-2021-31581 vulnerability is a security flaw discovered in the Akkadian Provisioning Manager Engine (PME) software. It is a remote code execution vulnerability that can be exploited by attackers to escape the restricted shell and gain unauthorized access to the system. The vulnerability exists in the 'Edit MySQL Configuration' command, which allows users to launch a standard vi editor interface that can be exploited by attackers to bypass security measures and gain unauthorized access to the system.

The exploitation of the CVE-2021-31581 vulnerability can lead to the compromise of sensitive data, the disruption of critical services, and the unauthorized granting of user privileges. Attackers can use this vulnerability to gain complete control over the system, execute arbitrary code, and perform a range of malicious activities. PME-based systems that are vulnerable to this exploit are at a significant risk of attack from cyber-criminals.

Thanks to the pro features of the s4e.io platform, users can quickly and easily identify vulnerabilities and other security threats in their digital assets. By leveraging the platform's advanced scanning tools and expert analysis, users can stay ahead of potential security threats and safeguard their systems from attack. With s4e.io, users can rest assured that their digital assets are protected from even the most advanced cyber-criminals.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-31581 vulnerability and other potential security threats, the following precautions can be taken:

  • Upgrade PME to version 3.0 or later, Akkadian Provisioning Manager 5.0.2 or later, and Akkadian Appliance Manager 3.3.0.314-4a349e0 or later
  • Disable access to the 'Edit MySQL Configuration' command, if not in use
  • Implement network segmentation to restrict access to PME-based systems
  • Implement multi-factor authentication to prevent unauthorized access
  • Regularly patch and update systems to ensure that security vulnerabilities are addressed

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-31581 scanner - OS Command Injection vulnerability in Akkadian Provisioning Manager Engine (PME) | S4E