Vulnerability Description
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Akkadianlabs | Ova Appliance | < 3.0 |
| Akkadianlabs | Provisioning Manager | >= 3.0.0, < 3.3.0.314-4a349e0 |
Related Weaknesses (CWE)
References
- https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multipExploitThird Party Advisory
- https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multipExploitThird Party Advisory
FAQ
What is CVE-2021-31580?
CVE-2021-31580 is a vulnerability with a CVSS score of 8.7 (HIGH). The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution para...
How severe is CVE-2021-31580?
CVE-2021-31580 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31580?
Check the references section above for vendor advisories and patch information. Affected products include: Akkadianlabs Ova Appliance, Akkadianlabs Provisioning Manager.