CRITICAL
CVE-2024-12356
CVSS
9.8
KEV
Description
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Summary dbcve.org
An unauthenticated command injection vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products allows attackers to inject and execute arbitrary commands as a site user without authentication. The critical CVSS 9.8 score reflects the ease of exploitation and high impact of arbitrary code execution.
Mitigation
Apply vendor patches immediately if available; otherwise, restrict network access to PRA/RS interfaces, implement WAF rules to detect command injection patterns, and monitor for unauthorized access attempts.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
87.99%
Probability of exploitation in next 30 days
99.8th percentile
References
https://nvd.nist.gov/vuln/detail/CVE-2024-12356
Third Party Advisory, US Government Resource
https://www.beyondtrust.com/trust-center/security-advisories/bt24-10
Vendor Advisory
https://www.cve.org/CVERecord?id=CVE-2024-12356
Third Party Advisory, US Government Resource
https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12356
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.