CVE-2021-45913
ControlUp Agent vulnerability analysis and mitigation

Overview

A hardcoded key vulnerability (CVE-2021-45913) was discovered in ControlUp Real-Time Agent (cuAgent.exe) before version 8.2.5. The vulnerability affects the authentication process between ControlUp Real-Time Console/Monitor and ControlUp Real-Time Agents. The issue was disclosed and patched on April 22, 2021 (Vendor Advisory).

Technical details

The vulnerability stems from the use of hardcoded keys in the authentication process between ControlUp Real-Time Console/Monitor and ControlUp Real-Time Agents. The hardcoded key could be extracted from a ControlUp Real-Time Console/Monitor binary file. The vulnerability has been assigned a CVSS v3.1 base score of 7.2 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) (NVD).

Impact

An attacker who extracts the hardcoded key could craft a fake ControlUp Real-Time Console/Monitor that would be able to successfully authenticate to ControlUp Real-Time Agents. This would allow the attacker to execute malicious operating system commands with SYSTEM level privileges on machines with vulnerable ControlUp Real-Time Agents installed (Vendor Advisory).

Mitigation and workarounds

ControlUp strongly recommends upgrading to version 8.5.1 for Hybrid Cloud or 8.5 for On-Premises installations. All ControlUp Real-Time Agents should be updated or uninstalled, even if they are no longer in use, as agents with versions lower than 8.5 can put organizations at risk even without an active Console/Monitor connection (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related ControlUp Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-45913HIGH7.2
  • ControlUp AgentControlUp Agent
  • cpe:2.3:a:controlup:controlup_agent
NoYesJan 04, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management