Tag: Privileged Remote Access (PRA)

CISA orders agencies to patch BeyondTrust bug exploited in attacks
News

CISA orders agencies to patch BeyondTrust bug exploited in attacks

A command injection flaw in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) has been identified by CISA as being actively abused in attacks (CVE-2024-12686). The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog and, as required by the Binding Operational Directive (BOD) 22-01, U.S. federal agencies have three weeks by February 3 to protect their networks from continuing assaults that target the vulnerability. Additionally, a significant command injection security flaw (CVE-2024-12356) was introduced in the same BeyondTrust software products by the U.S. cybersecurity agency on December 19 read more about CISA orders agencies to patch BeyondTrust bug exploited in attacks. Get up to date on the latest cybersecurity news and enhance your ...
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
News

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security flaw affecting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) database on Thursday, citing evidence of active exploitation in the field. CVE-2024-12356 (CVSS score: 9.8) is a command injection vulnerability that might be used by an attacker to run arbitrary commands while posing as the site user. CISA claims that BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) have a command injection vulnerability that could allow an unauthorized attacker to insert commands that are executed as site users read more about CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List. Get up to...