Microsoft Open Management Infrastructure RCE (CVE-2021-38647)

critical Nessus Plugin ID 153486

Version 1.135

Oct 23, 2025, 3:11 AM

  • Logic Changes (Fix HTTP/1 library to make sure it closes unused Keep-Alive connections)

Plugin Feed: 202510230311

Version 1.133

Oct 16, 2025, 4:39 PM

  • Logic Changes (Implement workaround in HTTP library to prevent triggering an engine bug.)

Plugin Feed: 202510161639

Version 1.131

Oct 8, 2025, 9:19 AM

  • Logic Changes (Allow forking plugins to report all installs for structured vuln data.)

Plugin Feed: 202510080919

Version 1.130

Oct 1, 2025, 9:12 PM

  • Logic Changes (Adding support for user-supplied header added to all HTTP requests.)

Plugin Feed: 202510012112

Version 1.129

Sep 30, 2025, 12:41 AM

  • Logic Changes (Add extra checks to see whether plugins should run. Modernisation of the HTTP/1 library. Various corrections and fixes for CPE related Flatline Test Failures. Remove spurious authentication header.)

Plugin Feed: 202509300041

Version 1.127

Jul 15, 2025, 2:39 AM

  • Logic Changes

Plugin Feed: 202507150239

Version 1.126

Jul 10, 2025, 5:41 PM

  • Logic Changes (Windows CA support)

Plugin Feed: 202507101741

Version 1.125

Jun 27, 2025, 8:01 PM

  • Logic Changes

Plugin Feed: 202506272001

Version 1.124

Jun 23, 2025, 9:47 PM

  • Logic Changes

Plugin Feed: 202506232147

Version 1.123

Jun 16, 2025, 4:11 PM

  • Logic Changes (Validate X509 certificates against CA's CRL in preference to OCSP.)

Plugin Feed: 202506161611

Version 1.120

Feb 12, 2025, 3:29 PM

  • Logic Changes

Plugin Feed: 202502121529

Version 1.119

Feb 12, 2025, 1:58 AM

  • Logic Changes

Plugin Feed: 202502120158

Version 1.118

Feb 10, 2025, 4:00 PM

  • Logic Changes

Plugin Feed: 202502101600

Version 1.116

Jan 22, 2025, 5:44 PM

  • New

Plugin Feed: 202501221744

Version 1.114

Jan 13, 2025, 10:27 PM

  • New

Plugin Feed: 202501132227

Version 1.113

Jan 13, 2025, 7:38 PM

  • Logic Changes (Add display fix to structured reporting.)

Plugin Feed: 202501131938

Version 1.109

Dec 24, 2024, 11:44 AM

  • New

Plugin Feed: 202412241144

Version 1.108

Nov 22, 2024, 6:54 PM

  • Logic Changes (Fixed installation reporting)

Plugin Feed: 202411221854

Version 1.107

Nov 12, 2024, 8:29 PM

  • Logic Changes (Adding installs report)

Plugin Feed: 202411122029

Version 1.105

Oct 29, 2024, 8:44 PM

  • Logic Changes (Extend structured reporting to vcf_extras)

Plugin Feed: 202410292044

Version 1.101

Oct 10, 2024, 11:57 PM

  • New

Plugin Feed: 202410102357

Version 1.100

Oct 9, 2024, 5:56 PM

  • Logic Changes (Corrects vulnerability-finding structured data tags to include the port.)

Plugin Feed: 202410091756

Version 1.96

Oct 3, 2024, 6:29 PM

  • Detection (Adding hardware constraint support to VCF and UCF)

Plugin Feed: 202410031829

Version 1.95

Oct 2, 2024, 4:10 PM

  • Logic Changes (Adds structured data reports to a subset of manual plugins.)

Plugin Feed: 202410021610

Version 1.94

Sep 11, 2024, 5:35 PM

  • New (Detects QUIC servers running on the target. Implement a NASL QUIC library to support detection of HTTP/3 and possibly more)

Plugin Feed: 202409111735

Version 1.93

Sep 3, 2024, 11:47 PM

  • Logic Changes (additional data collection for runtime scanning. fixed logic bug causing potential false negatives. fixed logic bug causing potential false positives. fixed logic bug with potential to break cyberark logins)

Plugin Feed: 202409032347

Version 1.91

Aug 14, 2024, 8:33 PM

  • Logic Changes (Endianness fix in Kerberos authentication for SCAP scanning)

Plugin Feed: 202408142033

Version 1.87

Jul 17, 2024, 11:02 PM

  • Logic Changes

Plugin Feed: 202407172302

Version 1.83

May 20, 2024, 10:13 AM

  • Logic Changes

Plugin Feed: 202405201013

Version 1.80

Mar 19, 2024, 6:40 PM

  • Logic Changes (Improving logging to reduce disk space usage)

Plugin Feed: 202403191840

Version 1.76

Feb 9, 2024, 11:22 AM

  • New

Plugin Feed: 202402091122

Version 1.75

Jan 16, 2024, 8:55 PM

  • Logic Changes (Improving debug logging)

Plugin Feed: 202401162055

Version 1.74

Jan 16, 2024, 5:39 PM

  • Detection (Support privacy mode DCOM over Kerberos)
  • Logic Changes (Improving debug logging)

Plugin Feed: 202401161739

Version 1.72

Nov 14, 2023, 4:21 PM

  • Detection (Support SHA2 based encryption for Kerberos)

Plugin Feed: 202311141621

Version 1.69

Sep 26, 2023, 8:16 PM

  • Logic Changes

Plugin Feed: 202309262016

Version 1.66

Jul 24, 2023, 7:10 PM

  • Logic Changes (added debugging)

Plugin Feed: 202307241910

Version 1.65

Jul 17, 2023, 5:15 PM

  • Logic Changes (Make torture_cgi library PCP clean and consolidate utf16_to_ascii())

Plugin Feed: 202307171715

Version 1.64

Jul 10, 2023, 7:11 PM

  • Logic Changes (Restrict ClientHello ciphersuites by encapsulation)

Plugin Feed: 202307101911

Version 1.63

Jul 7, 2023, 3:59 PM

  • Logic Changes (vcf conversion)

Plugin Feed: 202307071559

Version 1.62

Jun 20, 2023, 9:07 PM

  • Logic Changes (Temporarily limit debug logging)

Plugin Feed: 202306202107

Version 1.59

Jun 1, 2023, 5:27 AM

  • Logic Changes (Better logging)

Plugin Feed: 202306010527

Version 1.56

May 16, 2023, 7:02 PM

  • Detection (Authenticate WMI/DCOM using Kerberos credentials.)

Plugin Feed: 202305161902

Version 1.54

May 1, 2023, 9:07 PM

  • Detection (Make and use compatibility wrapper for running commands on scanner localhost to handle deprecation of pread().)

Plugin Feed: 202305012107

Version 1.51

Apr 6, 2023, 6:58 PM

  • Detection (Add Kerberos debug logging)

Plugin Feed: 202304061858

Version 1.48

Mar 8, 2023, 1:05 AM

  • Logic Changes

Plugin Feed: 202303080105

* Changelogs are generally available for changes made after Nov 1, 2022