CVE-2025-0217: Privileged Remote Access Authentication Bypass
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0217?
CVE-2025-0217 has been classified as a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2025-0217?
To mitigate CVE-2025-0217, upgrade to BeyondTrust Privileged Remote Access version 25.1 or later.
Who is affected by CVE-2025-0217?
CVE-2025-0217 affects users of BeyondTrust Privileged Remote Access versions prior to 25.1.
What type of attack is associated with CVE-2025-0217?
CVE-2025-0217 involves a local authentication bypass that can be exploited by an authenticated attacker.
What can an attacker do if they exploit CVE-2025-0217?
An attacker exploiting CVE-2025-0217 can view sensitive connection details of ShellJump sessions initiated with external tools.