Impact
A high‑severity flaw exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access. The vulnerability arises from insufficient validation of user‑supplied input parameters, enabling an authenticated attacker with limited privileges to access resources or data beyond their authorized scope. The flaw is classified as CWE‑943, indicating that should be protected.
Affected Systems
BeyondTrust’s Privilege Remote Access and Remote Support products are affected. The advisory does not specify particular releases, so any deployment of these products may be at risk unless the vendor confirms otherwise.
Risk and Exploitability
The CVSS score of 8.5 denotes high severity, yet the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s requires an authenticated account with certain permissions, the likely attack vector is internal or involves compromised credentials; if exploited, the attacker could read or manipulate privileged resources, compromising confidentiality and integrity.
OpenCVE Enrichment