A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://controlup.com | vendor advisory |
https://www.controlup.com/security/security-advisory-hardcoded-key/ | patch vendor advisory |