CVE-2024-12356

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*

History

17 Feb 2025, 21:15

Type Values Removed Values Added
References
  • () https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis -

20 Dec 2024, 15:25

Type Values Removed Values Added
First Time Beyondtrust
Beyondtrust remote Support
Beyondtrust privileged Remote Access
CPE cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*
cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
References () https://nvd.nist.gov/vuln/detail/CVE-2024-12356 - () https://nvd.nist.gov/vuln/detail/CVE-2024-12356 - Third Party Advisory, US Government Resource
References () https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 - () https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2024-12356 - () https://www.cve.org/CVERecord?id=CVE-2024-12356 - Third Party Advisory, US Government Resource

20 Dec 2024, 02:00

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto una vulnerabilidad crítica en los productos Privileged Remote Access (PRA) and Remote Support (RS) que puede permitir que un atacante no autenticado inyecte comandos que se ejecutan como un usuario del sitio.

17 Dec 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-17 05:15

Updated : 2025-02-17 21:15


NVD link : CVE-2024-12356

Mitre link : CVE-2024-12356

CVE.ORG link : CVE-2024-12356


JSON object : View

Products Affected

beyondtrust

  • privileged_remote_access
  • remote_support
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')