QID 730204
Date Published: 2021-09-20
QID 730204: Open Management Infrastructure (OMI) Remote Code Execution Vulnerability (OMIGOD)(Unauthenticated)
Open Management Infrastructure (OMI) is an open source project to further the development of a production quality implementation of the DMTF CIM/WBEM standards. The OMI CIMOM is also designed to be portable and highly modular. In order to attain its small footprint.
The vulnerability allows attacker to craft a malicious SOAP payload with no Authentication header specified which results in remote code execution with root privileges.
Affected Software:
Open Management Infrastructure versions prior to v1.6.8-1
QID Detection Logic (Unauthenticated):
This QID send a crafted HTTP POST request to "/wsman" endpoint to see if it executes Shell commands in order to identify vulnerable targets.
Successful exploitation allows Remote Code Execution.
- CVE-2021-38647 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-38647
CVEs related to QID 730204
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-38647 |
|