CVE-2025-5309
- EPSS 0.25%
- Veröffentlicht 16.06.2025 16:06:14
- Zuletzt bearbeitet 21.08.2025 20:36:00
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
CVE-2025-0217
- EPSS 0.02%
- Veröffentlicht 05.05.2025 17:00:05
- Zuletzt bearbeitet 01.08.2025 21:32:27
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing ...
CVE-2024-12686
- EPSS 15.1%
- Veröffentlicht 18.12.2024 21:15:08
- Zuletzt bearbeitet 14.01.2025 16:10:03
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
CVE-2024-12356
- EPSS 93.69%
- Veröffentlicht 17.12.2024 05:15:06
- Zuletzt bearbeitet 10.03.2025 20:27:00
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
CVE-2023-23632
- EPSS 0.01%
- Veröffentlicht 12.10.2023 20:15:12
- Zuletzt bearbeitet 21.11.2024 07:46:34
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump ite...
CVE-2023-4310
- EPSS 1.22%
- Veröffentlicht 05.09.2023 21:15:47
- Zuletzt bearbeitet 21.11.2024 08:34:49
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow a...