Lucene search

K
cve[email protected]CVE-2021-31581
HistoryJul 22, 2021 - 7:15 p.m.

CVE-2021-31581

2021-07-2219:15:08
CWE-312
CWE-269
web.nvd.nist.gov
77
3
cve-2021-31581
akkadian provisioning manager
akkadian pme
security vulnerability
ova appliance
akkadian appliance manager

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

7.9 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

4.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.6%

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the ‘Edit MySQL Configuration’ command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

Affected configurations

NVD
Node
akkadianlabsova_applianceRange<3.0
OR
akkadianlabsprovisioning_managerRange3.0.03.3.0.314-4a349e0
OR
akkadianlabsprovisioning_managerRange4.0.05.0.2

CNA Affected

[
  {
    "product": "Provisioning Manager Engine (PME)",
    "vendor": "Akkadian",
    "versions": [
      {
        "lessThanOrEqual": "4.50.18",
        "status": "affected",
        "version": "4.50.18",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

7.9 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

4.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.6%