S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-38647 Scanner

CVE-2021-38647 scanner - Remote Code Execution (RCE) vulnerability in Azure Open Management Infrastructure

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-38647
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Azure Automation State Configuration, DSC Extensionby Microsoft
AFFECTED< DSC Agent versions: 2.71.1.25, 2.70.0.30, 3.0.0.3SAFE ✓≥ DSC Agent versions: 2.71.1.25, 2.70.0.30, 3.0.0.3
Azure Automation Update Managementby Microsoft
AFFECTED< OMS Agent for Linux GA v1.13.40-0SAFE ✓≥ OMS Agent for Linux GA v1.13.40-0
Azure Diagnostics (LAD)by Microsoft
AFFECTED< LAD v4.0.13 and LAD v3.0.135SAFE ✓≥ LAD v4.0.13 and LAD v3.0.135
Azure Security Centerby Microsoft
AFFECTED< OMS Agent for Linux GA v1.13.40-0SAFE ✓≥ OMS Agent for Linux GA v1.13.40-0
Updated Aug 19, 2026View on NVD →
Detail

The Azure Open Management Infrastructure is a management solution designed by Microsoft to help users keep track of their digital assets. It is used to manage and monitor a wide range of resources, including virtual machines, applications, and networks. The solution is commonly used by organizations to handle their IT services efficiently and with ease. Azure Open Management Infrastructure is especially useful for those who operate cloud infrastructures, as it allows them to monitor and manage multiple cloud resources in one place.

CVE-2021-38647 is a critical remote execution vulnerability that was detected in the Azure Open Management Infrastructure. This vulnerability allows an attacker to execute arbitrary code remotely and gain complete control over the targeted system. Specifically, this vulnerability is caused by a flaw in the Open Management Infrastructure agent that failed to validate the inputs received from users, enabling malicious actors to exploit it easily.

If exploited, the CVE-2021-38647 vulnerability could lead to devastating consequences for organizations. Hackers could gain unauthorized access to sensitive data and cause data breaches. The vulnerability could also enable attackers to deploy malware, ransomware or steal valuable corporate or personal information.

With s4e.io, individuals can easily and quickly learn about vulnerabilities in their digital assets. Its pro features can help companies gain a better understanding of their security position, keeping them one step ahead of potential vulnerabilities. With detailed reports of potential vulnerabilities in their assets, s4e.io ensures that companies have the ability to address those vulnerabilities effectively and efficiently, before they become exploited and lead to data breaches.

 

REFERENCES

Solution Advice

The best way to mitigate this vulnerability is to apply the following preventive measures:

  • Update the software: Ensure that the Azure Open Management Infrastructure agent is updated to the latest version, which includes a fix to the vulnerability.
  • Network Protection: Use a firewall or intrusion prevention system to limit unapproved access to your network from untrusted sources.
  • Access Control: Restrict access to sensitive information and resources to only authorized personnel.
  • Password Policy: Use strong passwords and enforce frequent password changes for all user accounts.
  • Regular Auditing: Regularly audit logs and perform scans to detect any potential vulnerabilities and threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-38647 scanner - Remote Code Execution (RCE) vulnerability in Azure Open Management Infrastructure | S4E