A command injection flaw in BeyondTrust’s Privileged Remote Access (PRA) and Remote Support (RS) has been identified by CISA as being actively abused in attacks (CVE-2024-12686).
The vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog and, as required by the Binding Operational Directive (BOD) 22-01, U.S. federal agencies have three weeks by February 3 to protect their networks from continuing assaults that target the vulnerability.
Additionally, a significant command injection security flaw (CVE-2024-12356) was introduced in the same BeyondTrust software products by the U.S. cybersecurity agency on December 19 read more about CISA orders agencies to patch BeyondTrust bug exploited in attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
