PT-2022-12462 · Controlup · Controlup Real-Time Agent

James Burton

+1

·

Published

2022-01-04

·

Updated

2022-01-14

·

CVE-2021-45912

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Controlup Real-Time Agent versions prior to 8.5
Description The issue concerns an unauthenticated Named Pipe channel in the Controlup Real-Time Agent, potentially allowing an attacker to run OS commands via the ProcessActionRequest WCF method.
Recommendations For versions prior to 8.5, update to version 8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Named Pipe channel to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45912

Affected Products

Controlup Real-Time Agent