9.8
CVE-2023-4310
- EPSS 1.22%
- Published 05.09.2023 21:15:47
- Last modified 21.11.2024 08:34:49
- Source 9119a7d8-5eab-497f-8521-727c67
- Teams watchlist Login
- Open Login
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.
Data is provided by the National Vulnerability Database (NVD)
Beyondtrust ≫ Privileged Remote Access Version23.2.1
Beyondtrust ≫ Privileged Remote Access Version23.2.2
Beyondtrust ≫ Remote Support Version23.2.1
Beyondtrust ≫ Remote Support Version23.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.22% | 0.779 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.