CVE-2021-38647, dubbed "OMIGOD," is a critical Remote Code Execution (RCE) vulnerability affecting the Open Management Infrastructure (OMI) agent used across various Microsoft Azure services, including Azure Automation, Diagnostics, and Security Center. With a CVSS score of 9.8 (CRITICAL), it allows unauthenticated attackers to execute arbitrary code remotely with high privileges due to a network-adjacent authentication bypass. This vulnerability is actively exploited in the wild, notably by ransomware campaigns, and readily available exploit modules exist in tools like Metasploit and Nuclei. The high EPSS score, extensive media coverage, and community discussion underscore its significant risk and widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_diagnostics_\(lad\):-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_open_management_infrastructure:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.