CVE-2023-23632

HIGH

BeyondTrust Privileged Remote Access 22.2.1-22.3.3 - Local Authentication Bypass via BYOT Shell Jump Session

Title source: llm
STIX 2.1

Description

BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 9.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
beyondtrust/privileged_remote_access 22.2.1 - 22.3.3
Published Oct 12, 2023
Tracked Since Feb 18, 2026