Executive brief
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability (CWE-77). An unauthenticated attacker can inject commands that execute with the privileges of a site user.
Affected products
- BeyondTrust Privileged Remote Access (PRA) up to (including) 24.3.1
- BeyondTrust Remote Support (RS) up to (including) 24.3.1
Timeline
- 2024-12-17: disclosed: CVE received from BeyondTrust and published to NVD
- 2024-12-19: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2024-12-19: advisory: Vendor advisory BT24-10 published