← Back to browse · API

CVE-2024-12356

Severity
CRITICAL
CVSS
9.8
EPSS
0.87991
Risk score
95.0
CISA KEV
Yes
PoC
No
Published
2024-12-19
Modified
2024-12-19
First seen
2026-08-07
Aliases
EUVD-2024-50801, GHSA-69C6-CCV7-V3G3
Products
BeyondTrust:Privileged Remote Access (PRA) and Remote Support (RS), BeyondTrust:Privileged Remote Access 0 ≤24.3.1, BeyondTrust:Remote Support 0 ≤24.3.1
Sources
euvd EUVD-2024-50801
cisa.gov CVE-2024-12356

Description

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

References