Impact
A pre‑authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support and BeyondTrust Privileged Remote Access allows an attacker to bypass authentication checks before the user is verified. Improper validation of authentication data may enable a network‑positioned attacker to gain unauthorized control of the appliance and to assume accounts with elevated privileges. The weakness is a classical authentication bypass (CWE‑287).
Affected Systems
The flaw affects both BeyondTrust Privileged Remote Access and BeyondTrust Remote Support; the advisory does not list specific product versions, so administrators should review the vendor’s release notes to identify whether their deployed versions contain the fix.
Risk and Exploitability
The CVSS score of 9.2 classifies the vulnerability as critical. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not present in the CISA KEV catalog, meaning no public exploits are known. The attack requires an attacker that can reach the appliance over the network and the presence of a specific authentication configuration that triggers the bypass. Based on the description, it is inferred that the most likely attack vector is a network‑based attempt against the vulnerable authentication service in a setting where the vulnerable configuration is enabled.
OpenCVE Enrichment