CVE-2024-12686

medium

Description

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

References

https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/

https://www.beyondtrust.com/trust-center/security-advisories/bt24-11

https://nvd.nist.gov/vuln/detail/CVE-2024-12686

Details

Source: Mitre, NVD

Published: 2024-12-18

Updated: 2024-12-18

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 6.6

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: Medium