Impact
A critical flaw in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access wrongly processes authentication requests, allowing an unauthenticated attacker to bypass login controls and gain elevated access to the appliance. This weakness is classified as an authentication bypass (CWE‑287).
Affected Systems
Both BeyondTrust Privileged Remote Access and BeyondTrust Remote Support are impacted. The advisory does not specify particular software versions, so it is inferred that any current installation with the vulnerable authentication configuration enabled could be affected, even though the exact versions are not enumerated.
Risk and Exploitability
The vulnerability has a CVSS score of 9.2, labeling it as critical. Its EPSS score is below 1 %, indicating a very low likelihood of exploitation in the wild at present, and it is not listed in CISA KEV. The attack is remote and unauthenticated, requiring only that the vulnerable authentication configuration be enabled; exploitation could provide full control of the appliance, enable data disclosure, and potentially allow pivoting to other systems.
OpenCVE Enrichment