CVE-2021-38648🔥 Known Exploited (CISA KEV)HIGH7.8CVSS Severity ScoreEPSS Score26.8460%EPSS Percentile93.53thPublished2021-09-15Last Modified2025-10-30Data SourcesNVDCISA KEVFIRST.org EPSSVulnerability DescriptionOpen Management Infrastructure Elevation of Privilege VulnerabilityAffected Platforms (CPE)📦MicrosoftAzure Automation State ConfigurationAll versions📦MicrosoftAzure Automation Update ManagementAll versions📦MicrosoftAzure Diagnostics \(lad\)All versions📦MicrosoftAzure Open Management InfrastructureAll versionsShow All Affected Platforms (+6 more)References & Advisories🔗 http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html🔗 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648🔗 http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html🔗 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648🔗 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648