CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Dec 27, 2024
CVE-2024-12356
High
EPSS 93.8%CISA KEVDescription
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
EPSS — Exploit Probability
93.8%
Higher than 99.9% of all CVEs
Required Action
https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12356
Risk Assessment
HIGHIn CISA KEV
High EPSS
Details
- Severity
- High
- EPSS
- 93.8%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Dec 19, 2024
Added to KEV
Dec 19, 2024
Remediation Due
Dec 27, 2024
Affected Product
BeyondTrust
Privileged Remote Access (PRA) and Remote Support (RS)
View all BeyondTrust CVEs