CVE-2021-38647
KEV RANSOMWARECRITICAL 9.8EPSS 99.9%
Open Management Infrastructure Remote Code Execution Vulnerability
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.93% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-287
- Published
- 2021-09-15
- Updated
- 2026-08-10
Proof-of-concept exploits (13)
- http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentica…
- AlteredSecurity/CVE-2021-3864767★ · 2021-09-26
- Immersive-Labs-Sec/cve-2021-386472★ · 2021-09-16
- SimenBai/CVE-2021-38647-POC-and-Demo-environment3★ · 2021-09-22
- Vulnmachines/OMIGOD_cve-2021-386471★ · 2022-07-26
- Whiteh4tWolf/OMIGOD0★ · 2024-04-10
- abousteif/cve-2021-386470★ · 2021-09-22
- corelight/CVE-2021-386475★ · 2022-02-11
- corelight/CVE-2021-38647-noimages0★ · 2024-03-13
- fr34kyy/omigod1★ · 2021-09-26
- goofsec/omigod1★ · 2021-09-26
- horizon3ai/CVE-2021-38647233★ · 2021-09-16
- midoxnet/CVE-2021-386478★ · 2021-09-15