First published: Mon May 05 2025(Updated: )
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
Credit: 13061848-ea10-403d-bd75-c83a022c2891
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Privileged Remote Access | <25.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0217 has been classified as a high severity vulnerability due to the potential for unauthorized access.
To mitigate CVE-2025-0217, upgrade to BeyondTrust Privileged Remote Access version 25.1 or later.
CVE-2025-0217 affects users of BeyondTrust Privileged Remote Access versions prior to 25.1.
CVE-2025-0217 involves a local authentication bypass that can be exploited by an authenticated attacker.
An attacker exploiting CVE-2025-0217 can view sensitive connection details of ShellJump sessions initiated with external tools.