Lucene search

K
cvelistRapid7CVELIST:CVE-2021-31581
HistoryJul 22, 2021 - 6:27 p.m.

CVE-2021-31581 Akkadian Provisioning Manager Engine (PME) Shell Escape via 'vi' editor interface

2021-07-2218:27:19
CWE-269
rapid7
www.cve.org
2

7.9 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

7.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.6%

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the ‘Edit MySQL Configuration’ command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

CNA Affected

[
  {
    "product": "Provisioning Manager Engine (PME)",
    "vendor": "Akkadian",
    "versions": [
      {
        "lessThanOrEqual": "4.50.18",
        "status": "affected",
        "version": "4.50.18",
        "versionType": "custom"
      }
    ]
  }
]

7.9 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

7.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.6%

Related for CVELIST:CVE-2021-31581