← Back to CVE List
Vulnerability Intelligence Report
Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)

CVE-2024-12686

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
6.6
MEDIUM
Exploitability:0.8
Impact Score:5.9
EPSS Probability:13.79%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) 0 <= 24.3.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
13.788%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityBeyondTrust Inc. · Vendor · USA
Reserved2024-12-16T18:58:57
Published2024-12-18T20:23:57
Patch Date2024-12-18
Last Updated2025-10-21T22:55:34

LINK COPIED TO CLIPBOARD