Tag: injection vulnerability

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
News

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security flaw affecting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) database on Thursday, citing evidence of active exploitation in the field. CVE-2024-12356 (CVSS score: 9.8) is a command injection vulnerability that might be used by an attacker to run arbitrary commands while posing as the site user. CISA claims that BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) have a command injection vulnerability that could allow an unauthorized attacker to insert commands that are executed as site users read more about CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List. Get up to...