CyberzSOC

Applicability
← Back to CVE-2021-38649

CVE-2021-38649

In CISA KEV Microsoft

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

OSV.dev (incl. GHSA)
precedence 80 · revised 2026-08-12
1 affected 1 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2026-08-10
10 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (12)

Product Status Versions Remediation Source
https://github.com/microsoft/omi affected < 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa vendor fix → 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa osv
https://github.com/microsoft/omi fixed 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa vendor fix → 4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa osv
Microsoft/Azure Automation State Configuration, DSC Extension Microsoft · Azure Automation State Configuration, DSC Extension affected >= 2.0.0, < DSC Agent versions: 2.71.1.25, 2.70.0.30, 3.0.0.3 none available cve_cna
Microsoft/Azure Automation Update Management Microsoft · Azure Automation Update Management affected >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 none available cve_cna
Microsoft/Azure Diagnostics (LAD) Microsoft · Azure Diagnostics (LAD) affected >= 3.0.0, < LAD v4.0.13 and LAD v3.0.135 none available cve_cna
Microsoft/Azure Security Center Microsoft · Azure Security Center affected >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 none available cve_cna
Microsoft/Azure Sentinel Microsoft · Azure Sentinel affected >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 none available cve_cna
Microsoft/Azure Stack Hub Microsoft · Azure Stack Hub affected >= 1.0.0, < Monitor, Update and Config Mgmnt 1.14.01 none available cve_cna
Microsoft/Container Monitoring Solution Microsoft · Container Monitoring Solution affected 1.0.0 none available cve_cna
Microsoft/Log Analytics Agent Microsoft · Log Analytics Agent affected >= 1.0.0, < OMS Agent for Linux GA v1.13.40-0 none available cve_cna
Microsoft/Open Management Infrastructure Microsoft · Open Management Infrastructure affected >= 16.0, < OMI Version 1.6.8-1 none available cve_cna
Microsoft/System Center Operations Manager (SCOM) Microsoft · System Center Operations Manager (SCOM) affected >= 1.0.0, < OMI version: 1.6.8-1 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.