Remote Support

Vendor:

First CVE: Oct 26, 2017 · Active for 8 years

10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
30.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Remote Support over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2017
8 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

CVE Severity & Scoring

Remote Support10 CVEs
All CVEs352,294 CVEs
HighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None8 (80.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s
Feb 6, 20269.898YESYES
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that
Dec 17, 20249.898YESYES
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands
Dec 18, 20247.270YESNO
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauth
Jul 6, 20269.846NONO
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters
Jul 6, 20269.943NONO
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication
Jul 6, 20268.142NONO
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of
Jul 6, 20267.537NONO
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code executi
Jun 16, 20259.831NONO
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious H
Sep 5, 20239.830NONO
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
Oct 26, 20177.820NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
3 CVEs
30.0% of CVEs· 98th percentile
Metasploit
2 CVEs
20.0% of CVEs· 97th percentile
Nuclei
2 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Remote Support

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
25.1.119.80.9%00
23.2.219.81.4%00
23.2.119.81.4%00
16.2.217.81.3%00
16.2.117.81.3%00
16.1.417.81.3%00
16.1.317.81.3%00
16.1.217.81.3%00
16.1.117.81.3%00
15.2.217.81.3%00
15.2.117.81.3%00