Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-0217


BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.


Published

2025-05-05T17:18:46.720

Last Modified

2025-11-03T20:17:05.713

Status

Modified

Source

13061848-ea10-403d-bd75-c83a022c2891

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application beyondtrust privileged_remote_access < 25.1 Yes

References