Technical Severity
MEDIUM
CVSS v3.1 Metrics
6.6
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood
EPSS Prediction
36.99
%
Predictive Probability
Percentile Rank
97.0
th
Documented as more likely to be exploited than 97.0% of known CVEs.
Detection Date
Jan 13, 2025
Remediation Due
Feb 03, 2025
CISA Catalog Active
Threat Analysis
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.