CVE-2023-23632
HIGHBeyondTrust Privileged Remote Access 22.2.1-22.3.3 - Local Authentication Bypass via BYOT Shell Jump Session
Title source: llmDescription
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.
References (2)
Core 2
Core References
Third Party Advisory
https://www.compass-security.com/fileadmin/Research/Advisories/2023_03_CSNC-2022-018_PRA_Privilege_Escalation.txt
Mailing List
http://seclists.org/fulldisclosure/2025/May/1
Scores
CVSS v3
7.8
EPSS
0.0019
EPSS Percentile
9.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (1)
beyondtrust/privileged_remote_access
22.2.1 - 22.3.3
Published
Oct 12, 2023
Tracked Since
Feb 18, 2026