CVE-2021-38647🔥 Known Exploited (CISA KEV)CRITICAL9.8CVSS Severity ScoreEPSS Score66.2790%EPSS Percentile89.95thPublished2021-09-15Last Modified2025-10-30Data SourcesNVDCISA KEVFIRST.org EPSSVulnerability DescriptionOpen Management Infrastructure Remote Code Execution VulnerabilityAffected Platforms (CPE)📦MicrosoftAzure Automation State ConfigurationAll versions📦MicrosoftAzure Automation Update ManagementAll versions📦MicrosoftAzure Diagnostics \(lad\)All versions📦MicrosoftAzure Open Management InfrastructureAll versionsShow All Affected Platforms (+6 more)References & Advisories🔗 http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.html🔗 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647🔗 http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.html🔗 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647🔗 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38647