CVE-2025-0217

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*

History

01 Aug 2025, 21:32

Type Values Removed Values Added
Summary
  • (es) Las versiones de Acceso Remoto Privilegiado (PRA) de BeyondTrust anteriores a la 25.1 son vulnerables a una omisión de autenticación local. Un atacante autenticado localmente puede ver los detalles de conexión de una sesión de ShellJump iniciada con herramientas externas, lo que permite el acceso no autorizado a las sesiones conectadas.
CPE cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://www.beyondtrust.com/trust-center/security-advisories/bt25-03 - () https://www.beyondtrust.com/trust-center/security-advisories/bt25-03 - Vendor Advisory
First Time Beyondtrust privileged Remote Access
Beyondtrust

05 May 2025, 17:18

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-05 17:18

Updated : 2025-08-01 21:32


NVD link : CVE-2025-0217

Mitre link : CVE-2025-0217

CVE.ORG link : CVE-2025-0217


JSON object : View

Products Affected

beyondtrust

  • privileged_remote_access
CWE
CWE-287

Improper Authentication