VYPR
Unrated severityCISA KEVNVD Advisory· Published Dec 17, 2024· Updated Oct 21, 2025

Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)

CVE-2024-12356

Description

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

Affected products

2
  • BeyondTrust/Remote Supportv5
    Range: 0
  • BeyondTrust/Privileged Remote Accessv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

1