Impact
BeyondTrust Remote Support and Privileged Remote Access contain a pre‑authentication vulnerability that allows an unauthenticated attacker to send malformed client‑supplied data to the appliance's network communication subsystem. Insufficient validation of that data can trigger a denial‑of-service condition, rendering the appliance unavailable and disrupting the service for all users that depend on it. The weakness is an input‑validation flaw classified as CWE‑400 and does not provide authentication bypass or data exfiltration capabilities.
Affected Systems
The vulnerability impacts BeyondTrust Remote Support and Privileged Remote Access products. No specific version information is provided, so any current or future releases may be susceptible until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk of denial of service. The EPSS score of <1% suggests that automated exploitation is presently unlikely. The vulnerability can be exploited from any location with network access to the appliance’s communication ports, as it is a pre‑authentication flaw. An attacker can send malformed client‑supplied data over the network to trigger a denial‑of-service condition, potentially bringing the appliance offline for all users. The weakness is not listed in CISA KEV.
OpenCVE Enrichment