Oct. 12, 2023, 8:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.

access attackers authentication authentication bypass beyondtrust bypass cve exploit local pra privileged process remote access secret sessions shell unauthorized access verification vulnerable

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Risk and compliance specialist

@ ZainCash | Baghdad, Baghdad Governorate, Iraq

Information Security Compliance Analyst

@ Evelyn Partners | Liverpool, United Kingdom

Director of Security Engineering

@ Kasada | Melbourne