BeyondTrust Privileged Remote Access (PRA) versions prior...
High severity
Unreviewed
Published
May 5, 2025
to the GitHub Advisory Database
•
Updated Aug 2, 2025
Description
Published by the National Vulnerability Database
May 5, 2025
Published to the GitHub Advisory Database
May 5, 2025
Last updated
Aug 2, 2025
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
References