HIGH · 7.9

CVE-2021-31581

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which...

Vulnerability Description

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

CVSS Score

7.9

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AkkadianlabsOva Appliance< 3.0
AkkadianlabsProvisioning Manager>= 3.0.0, < 3.3.0.314-4a349e0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-31581?

CVE-2021-31581 is a vulnerability with a CVSS score of 7.9 (HIGH). The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which...

How severe is CVE-2021-31581?

CVE-2021-31581 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-31581?

Check the references section above for vendor advisories and patch information. Affected products include: Akkadianlabs Ova Appliance, Akkadianlabs Provisioning Manager.