Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12356


A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.


Published

2024-12-17T05:15:06.413

Last Modified

2025-03-10T20:27:00.663

Status

Analyzed

Source

13061848-ea10-403d-bd75-c83a022c2891

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application beyondtrust privileged_remote_access ≤ 24.3.1 Yes
Application beyondtrust remote_support ≤ 24.3.1 Yes

References