Записи BeyondTrust
36 опубликованных записей вендора beyondtrust.
Профиль для исследователя
- Попали в KEV
- 4 · 11,1 %
- С эксплойтом
- 4 · 11,1 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 11,1 %
- Медиана: публикация → KEV
- 17 дн.
Повторяющиеся классы
- CWE-287 Improper Authentication4
- CWE-269 Improper Privilege Management3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-268 Privilege Chaining2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
96Срочно | CVE-2026-1731Готовый эксплойт | Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)beyondtrust · privileged remote access · CWE-78 | Критическая9,9 | KEV | 91,0 % | 6 февр. 2026 г. |
95Срочно | CVE-2024-12356Готовый эксплойт | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)beyondtrust · privileged remote access · CWE-77 | Критическая9,8 | KEV | 87,3 % | 17 дек. 2024 г. |
91Срочно | CVE-2021-3156Готовый эксплойт | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Высокая7,8 | KEV | 100,0 % | 26 янв. 2021 г. |
62На этой неделе | CVE-2024-12686Готовый эксплойт | Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)beyondtrust · privileged remote access · CWE-78 | Высокая7,2 | KEV | 13,7 % | 18 дек. 2024 г. |
40В плане | CVE-2023-4310Эксплойта нет | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability whicbeyondtrust · privileged remote access · CWE-77 | Критическая9,8 | — | 1,9 % | 5 сент. 2023 г. |
36Наблюдать | CVE-2026-40139Эксплойта нет | Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-287 | Критическая9,2 | — | 0,8 % | 6 июл. 2026 г. |
36Наблюдать | CVE-2026-40138Эксплойта нет | Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-287 | Критическая9,2 | — | 0,5 % | 6 июл. 2026 г. |
36Наблюдать | CVE-2024-4219Эксплойта нет | SSRF In BeyondInsightbeyondtrust · beyondinsight · CWE-918 | Критическая9,1 | — | 0,2 % | 4 июн. 2024 г. |
35Наблюдать | CVE-2020-12613Эксплойта нет | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows | Высокая8,8 | — | 0,8 % | 11 дек. 2023 г. |
35Наблюдать | CVE-2021-3187Эксплойта нет | An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7.beyondtrust · privilege management for mac · CWE-276 | Высокая8,8 | — | 0,6 % | 11 дек. 2023 г. |
34Наблюдать | CVE-2025-5309Эксплойта нет | Remote Support & Privileged Remote Access server side template injectionbeyondtrust · privileged remote access · CWE-94 | Высокая8,6 | — | 0,9 % | 16 июн. 2025 г. |
34Наблюдать | CVE-2026-40140Эксплойта нет | High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-400 | Высокая8,7 | — | 0,6 % | 6 июл. 2026 г. |
34Наблюдать | CVE-2026-40141Эксплойта нет | High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-943 | Высокая8,5 | — | 0,5 % | 6 июл. 2026 г. |
32Наблюдать | CVE-2021-31589Proof of concept | A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 beyondtrust · appliance base software · CWE-79 | Средняя6,1 | — | 25,1 % | 5 янв. 2022 г. |
31Наблюдать | CVE-2017-5996Эксплойта нет | The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weakbeyondtrust · remote support · CWE-426 | Высокая7,8 | — | 1,3 % | 26 окт. 2017 г. |
31Наблюдать | CVE-2021-42254Эксплойта нет | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.beyondtrust · privilege management for windows · CWE-668 | Высокая7,8 | — | 0,3 % | 19 нояб. 2021 г. |
31Наблюдать | CVE-2020-12612Эксплойта нет | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows | Высокая7,8 | — | 0,3 % | 12 дек. 2023 г. |
31Наблюдать | CVE-2020-28369Эксплойта нет | In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the usebeyondtrust · privilege management for windows · CWE-427 | Высокая7,8 | — | 0,2 % | 12 дек. 2023 г. |
31Наблюдать | CVE-2020-12615Эксплойта нет | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows · CWE-269 | Высокая7,8 | — | 0,2 % | 12 дек. 2023 г. |
31Наблюдать | CVE-2023-23632Эксплойта нет | BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass.beyondtrust · privileged remote access · CWE-287 | Высокая7,8 | — | 0,2 % | 12 окт. 2023 г. |
31Наблюдать | CVE-2024-4017Эксплойта нет | Privilege Escalation in U-Series Appliancebeyondtrust · u-series appliance · CWE-269 | Высокая7,8 | — | 0,2 % | 19 апр. 2024 г. |
31Наблюдать | CVE-2024-4018Эксплойта нет | Privilege Escalation in U-Series Appliancebeyondtrust · u-series appliance · CWE-269 | Высокая7,8 | — | 0,2 % | 19 апр. 2024 г. |
31Наблюдать | CVE-2020-12614Эксплойта нет | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows · CWE-295 | Высокая7,8 | — | 0,1 % | 12 дек. 2023 г. |
31Наблюдать | CVE-2024-25083Эксплойта нет | An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1.beyondtrust · privilege management for windows · CWE-266 | Высокая7,8 | — | 0,1 % | 16 февр. 2024 г. |
30Наблюдать | CVE-2018-10959Эксплойта нет | Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environmenbeyondtrust · avecto defendpoint · CWE-426 | Высокая7,5 | — | 1,6 % | 17 апр. 2019 г. |
- CVE-2026-173196Срочно
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 91 %beyondtrust · privileged remote access6 февр. 2026 г.
- CVE-2024-1235695Срочно
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %beyondtrust · privileged remote access17 дек. 2024 г.
- CVE-2021-315691Срочно
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %sudo project · sudo26 янв. 2021 г.
- CVE-2024-1268662На этой неделе
Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 14 %beyondtrust · privileged remote access18 дек. 2024 г.
- CVE-2023-431040В плане
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability whic
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %beyondtrust · privileged remote access5 сент. 2023 г.
- CVE-2026-4013936Наблюдать
Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %beyondtrust · privileged remote access6 июл. 2026 г.
- CVE-2026-4013836Наблюдать
Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %beyondtrust · privileged remote access6 июл. 2026 г.
- CVE-2024-421936Наблюдать
SSRF In BeyondInsight
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %beyondtrust · beyondinsight4 июн. 2024 г.
- CVE-2020-1261335Наблюдать
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %beyondtrust · privilege management for windows11 дек. 2023 г.
- CVE-2021-318735Наблюдать
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %beyondtrust · privilege management for mac11 дек. 2023 г.
- CVE-2025-530934Наблюдать
Remote Support & Privileged Remote Access server side template injection
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %beyondtrust · privileged remote access16 июн. 2025 г.
- CVE-2026-4014034Наблюдать
High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %beyondtrust · privileged remote access6 июл. 2026 г.
- CVE-2026-4014134Наблюдать
High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %beyondtrust · privileged remote access6 июл. 2026 г.
- CVE-2021-3158932Наблюдать
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1
СредняяCVSS 6,1Proof of conceptEPSS 25 %beyondtrust · appliance base software5 янв. 2022 г.
- CVE-2017-599631Наблюдать
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %beyondtrust · remote support26 окт. 2017 г.
- CVE-2021-4225431Наблюдать
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows19 нояб. 2021 г.
- CVE-2020-1261231Наблюдать
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows12 дек. 2023 г.
- CVE-2020-2836931Наблюдать
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the use
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows12 дек. 2023 г.
- CVE-2020-1261531Наблюдать
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows12 дек. 2023 г.
- CVE-2023-2363231Наблюдать
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privileged remote access12 окт. 2023 г.
- CVE-2024-401731Наблюдать
Privilege Escalation in U-Series Appliance
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · u-series appliance19 апр. 2024 г.
- CVE-2024-401831Наблюдать
Privilege Escalation in U-Series Appliance
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · u-series appliance19 апр. 2024 г.
- CVE-2020-1261431Наблюдать
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows12 дек. 2023 г.
- CVE-2024-2508331Наблюдать
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows16 февр. 2024 г.
- CVE-2018-1095930Наблюдать
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environmen
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %beyondtrust · avecto defendpoint17 апр. 2019 г.