Issued: Wednesday, 29 September, 2021 |
Last Revision: Wednesday, 29 September, 2021 |
Vendor: |
Product: |
Severity Level: |
The vulnerabilities, which are collectively referred to as “OMIGOD,” are found within OMI agents that are installed on Microsoft’s Azure Linux virtual machines (VMs) by default.
An unauthenticated, remote attacker can exploit the vulnerability (CVE-2021-38647) by sending a specially crafted request to a vulnerable host over a publicly accessible remote management port (ports 5986, 5985 and 1270). Successful exploitation would grant an attacker the ability to execute arbitrary code with root privileges on the vulnerable Linux VM.
As a result, CVE-2021-38647 vulnerability is the most severe out of the four flaws encompassing OMIGOD. We have already reported this vulnerability in Risk Directive R15092021000105 dated 15th Sep 21.
CVE-2021-38645, CVE-2021-38648 and CVE-2021-38649 are three elevation of privilege vulnerabilities in OMI.
CVE | Description | CVSS3.0 Score |
CVE-2021-38647 | Open Management Infrastructure Remote Code Execution Vulnerability | 9.8 |
CVE-2021-38645 | Open Management Infrastructure Elevation of Privilege Vulnerability | 7.8 |
CVE-2021-38648 | Open Management Infrastructure Elevation of Privilege Vulnerability | 7.8 |
CVE-2021-38649 | Open Management Infrastructure Elevation of Privilege Vulnerability | 7.0 |
Table 1: Vulnerability details
OMI Overview:
Open Management Infrastructure (OMI) is an open-source Web-Based Enterprise Management (WBEM) implementation for managing Linux and UNIX systems. Several Azure Virtual Machine (VM) management extensions use this framework to orchestrate configuration management and log collection on Linux VMs.
Vulnerability / CVE | Affected Product(s) |
CVE-2021-38647 CVE-2021-38645 CVE-2021-38648 CVE-2021-38649 | Azure Stack Hub Azure Sentinel Azure Security Center Container Monitoring Solution Azure Diagnostics (LAD) Log Analytics Agent Azure Automation Update Management Azure Automation State Configuration, DSC Extension System Center Operations Manager (SCOM) Azure Open Management Infrastructure |
Table 2: Vulnerable versions
Please apply the patches released in Sept 21 and refer the references for additional protection, to know the version of vulnerable OMI, PaaS service affected by OMI vulnerability and determine impacted VMs by these vulnerabilities.
