ZeroHour

CVE-2021-45912

CVSS 3.1
7.8 high
EPSS
<1%p22
Published
()
Modified
Description

An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.

Vendors
controlup
Products
real-time agent
Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.