KEV Entry

CVE-2021-38647

Known Exploited Vulnerability Entry Previdian

Entry Details
Confirmed Exploited

CVE-2021-38647

2021-11-03 01:00 CET


Timestamps

2021-11-03

2021-11-03


Scope

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Affected: Microsoft / Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | CVSS: 9.8 (CRITICAL) | EPSS: 0.99933 | Used in malware: yes | Not yet in CISA KEV: False


References
  • {'id': 'CVE-2021-38647', 'url': 'https://www.cve.org/CVERecord?id=CVE-2021-38647'}
  • {'id': 'GHSA-RP2G-5HW2-Q565', 'url': 'https://github.com/advisories/GHSA-RP2G-5HW2-Q565'}
  • {'id': 'previdian', 'url': 'https://previdian.com/CVE-2021-38647'}

9e7366d9-e505-41b7-8e7b-77676fd64489

Previdian
caeb2787-0d58-4236-9039-7c86c3e566f3

2026-10-02 09:10 CEST

2026-10-02 09:10 CEST

Evidence
1
Type Source Signal Confidence Details GCVE Metadata
public_report previdian confirmed_compromise 0.70
View details
{
  "added_date": "2021-11-03T00:00:00.000Z",
  "ahead_of_cisa_kev": null,
  "cve_id": "CVE-2021-38647",
  "cvss_estimated": false,
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "epss_percentile": 0.9997,
  "epss_score": 0.99933,
  "feed": "Previdian (previdian.com)",
  "ghsa_id": "GHSA-RP2G-5HW2-Q565",
  "not_yet_in_cisa_kev": false,
  "previous_ids": [],
  "product": "Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM)",
  "title": "Open Management Infrastructure (OMI) Remote Code Execution Vulnerability",
  "used_in_malware": "yes",
  "vendor": "Microsoft",
  "virtual_patch": false,
  "vulnerability_id": "CVE-2021-38647"
}
-