CVE-2024-12356: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Other sources
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12356?
CVE-2024-12356 is classified as a critical vulnerability.
How do I fix CVE-2024-12356?
To fix CVE-2024-12356, update BeyondTrust Privileged Remote Access and Remote Support to versions beyond 24.3.1.
What products are affected by CVE-2024-12356?
CVE-2024-12356 affects BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products.
Can CVE-2024-12356 be exploited remotely?
Yes, CVE-2024-12356 can be exploited remotely by an unauthenticated attacker.
What kind of attack does CVE-2024-12356 allow?
CVE-2024-12356 allows an attacker to inject commands that are executed as a site user.