BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.
References
Configurations
History
03 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 07:46
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-10-12 20:15
Updated : 2025-11-03 20:15
NVD link : CVE-2023-23632
Mitre link : CVE-2023-23632
CVE.ORG link : CVE-2023-23632
JSON object : View
Products Affected
beyondtrust
- privileged_remote_access
CWE
CWE-287
Improper Authentication
