Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/microsoft/omi | affected | < 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa | vendor fix → 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa | osv | |
| https://github.com/microsoft/omi | fixed | 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa | vendor fix → 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa | osv | |
| Microsoft/Azure Automation State Configuration, DSC Extension Microsoft · Azure Automation State Configuration, DSC Extension | affected | >= 2.0.0, < DSC Agent versions: 2.71.1.25, 2.70.0.30, 3.0.0.3 | none available | cve_cna | |
| Microsoft/Azure Automation Update Management Microsoft · Azure Automation Update Management | affected | >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 | none available | cve_cna | |
| Microsoft/Azure Diagnostics (LAD) Microsoft · Azure Diagnostics (LAD) | affected | >= 3.0.0, < LAD v4.0.13 and LAD v3.0.135 | none available | cve_cna | |
| Microsoft/Azure Security Center Microsoft · Azure Security Center | affected | >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 | none available | cve_cna | |
| Microsoft/Azure Sentinel Microsoft · Azure Sentinel | affected | >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 | none available | cve_cna | |
| Microsoft/Azure Stack Hub Microsoft · Azure Stack Hub | affected | >= 1.0.0, < Monitor, Update and Config Mgmnt 1.14.01 | none available | cve_cna | |
| Microsoft/Container Monitoring Solution Microsoft · Container Monitoring Solution | affected | 1.0.0 | none available | cve_cna | |
| Microsoft/Log Analytics Agent Microsoft · Log Analytics Agent | affected | >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 | none available | cve_cna | |
| Microsoft/Open Management Infrastructure Microsoft · Open Management Infrastructure | affected | >= 16.0, < OMI Version 1.6.8-1 | none available | cve_cna | |
| Microsoft/System Center Operations Manager (SCOM) Microsoft · System Center Operations Manager (SCOM) | affected | >= 1.0.0, < OMI version: 1.6.8-1 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.