Impact
BeyondTrust Remote Support and Privileged Remote Access contain a pre‑authentication vulnerability that allows an unauthenticated attacker to send malformed client‑supplied data to the appliance's network communication subsystem. Insufficient validation of that data can trigger a denial‑of‑service condition, rendering the appliance unavailable and disrupting the service for all users that depend on it. The weakness is an input‑validation flaw classified as CWE‑400 and does not provide authentication bypass or data exfiltration capabilities.
Affected Systems
The vulnerability impacts BeyondTrust Remote Support and Privileged Remote Access products. No specific version information is provided, so any current or future releases may be susceptible until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk, but the EPSS score of less than 1% implies that automated exploitation is presently unlikely. The flaw can be abused over the network by sending crafted packets to the appliance’s communication ports, and it is not listed in the CISA KEV catalog. An attacker would only need unauthenticated network access to the appliance and could disrupt service availability for all users.
OpenCVE Enrichment