Lucene search

K
cveMitreCVE-2021-45912
HistoryJan 04, 2022 - 4:15 p.m.

CVE-2021-45912

2022-01-0416:15:09
CWE-78
mitre
web.nvd.nist.gov
16
cve-2021-45912
controlup real-time agent
cuagent.exe
os command execution
named pipe channel
wcf method

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

13.1%

An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.

Affected configurations

Nvd
Node
controlupreal-time_agentRange<8.5hybrid_cloud
OR
controlupreal-time_agentRange<8.5on-premises
VendorProductVersionCPE
controlupreal-time_agent*cpe:2.3:a:controlup:real-time_agent:*:*:*:*:hybrid_cloud:*:*:*
controlupreal-time_agent*cpe:2.3:a:controlup:real-time_agent:*:*:*:*:on-premises:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

13.1%

Related for CVE-2021-45912