« Volver al listado

Beyondtrust

Beyondtrust Privileged Remote Access: vulnerabilidades y CVE

Beyondtrust Privileged Remote Access tiene 11 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 5 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses5
Críticas5
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-1731Crítica (9.9)91%⚠ Explotación activa6 feb 2026
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an…
CVE-2024-12686Alta (7.2)14%⚠ Explotación activa18 dic 2024
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
CVE-2024-12356Crítica (9.8)87%⚠ Explotación activa17 dic 2024
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-40141Alta (8.5)0.53%—6 jul 2026
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of…
CVE-2026-40140Alta (8.7)0.65%—6 jul 2026
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an…
CVE-2026-40139Crítica (9.2)0.75%—6 jul 2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass…
CVE-2026-40138Crítica (9.2)0.46%—6 jul 2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned…
CVE-2026-1731Crítica (9.9)91%⚠ Explotación activa6 feb 2026
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an…
CVE-2025-5309Alta (8.6)0.95%—16 jun 2025
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
CVE-2025-0217Alta (7.3)0.19%—5 may 2025
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated…
CVE-2024-12686Alta (7.2)14%⚠ Explotación activa18 dic 2024
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
CVE-2024-12356Crítica (9.8)87%⚠ Explotación activa17 dic 2024
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
CVE-2023-23632Alta (7.8)0.19%—12 oct 2023
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing…
CVE-2023-4310Crítica (9.8)1.8%—5 sept 2023
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1190 Exploit Public-Facing Application2
  3. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Beyondtrust