Privileged Remote Access

Vendor:

First CVE: Sep 5, 2023 · Active for 2 years

11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 82% of tracked products
27.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Privileged Remote Access over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2023
2 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

CVE Severity & Scoring

Privileged Remote Access11 CVEs
All CVEs352,231 CVEs
HighCritical
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (27.3%)
High1 (9.1%)
None7 (63.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s
Feb 6, 20269.898YESYES
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that
Dec 17, 20249.898YESYES
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands
Dec 18, 20247.270YESNO
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauth
Jul 6, 20269.846NONO
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters
Jul 6, 20269.943NONO
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication
Jul 6, 20268.142NONO
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of
Jul 6, 20267.537NONO
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code executi
Jun 16, 20259.831NONO
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious H
Sep 5, 20239.830NONO
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of
May 5, 20257.824NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
3 CVEs
27.3% of CVEs· 98th percentile
Metasploit
2 CVEs
18.2% of CVEs· 97th percentile
Nuclei
2 CVEs
18.2% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Privileged Remote Access

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
25.1.119.80.9%00
23.2.219.81.4%00
23.2.119.81.4%00