CVE-2024-12356

CRITICAL KEV NUCLEI

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution

Title source: metasploit

Description

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

Exploits (3)

metasploit WORKING POC EXCELLENT
by Harsh Jaiswal, Jonah Burgess (CryptoCat) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/beyondtrust_pra_rs_command_injection.rb
metasploit WORKING POC EXCELLENT
by sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/beyondtrust_pra_rs_unauth_rce.rb

Nuclei Templates (1)

Privileged Remote Access & Remote Support - Command Injection
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch

Scores

CVSS v3 9.8
EPSS 0.9386
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-12-19
VulnCheck KEV 2024-12-19
InTheWild.io 2024-12-19
ENISA EUVD EUVD-2024-50801
CWE
CWE-77
Status published
Products (2)
beyondtrust/privileged_remote_access < 24.3.1
beyondtrust/remote_support < 24.3.1
Published Dec 17, 2024
KEV Added Dec 19, 2024
Tracked Since Feb 18, 2026