Description
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.
References (2)
Core 2
Core References
Scores
CVSS v3
9.8
EPSS
0.0141
EPSS Percentile
69.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (4)
beyondtrust/privileged_remote_access
23.2.1
beyondtrust/privileged_remote_access
23.2.2
beyondtrust/remote_support
23.2.1
beyondtrust/remote_support
23.2.2
Published
Sep 05, 2023
Tracked Since
Feb 18, 2026