BeyondTrust reveals appliance vulnerability

By
Follow google news

Cloud service already fixed.

A remote access management vulnerability has emerged in BeyondTrust appliances.

BeyondTrust reveals appliance vulnerability

The security advisory is available to customers only, but security researcher Brian Krebs has obtained and published a copy.

BeyondTrust’s senior VP for product management Sam Elliott confirmed the vulnerability to iTnews.

“During a recent test, we discovered a critical security vulnerability that requires immediate attention from our customers exclusively running Remote Support versions 23.2.1 and 23.2.2, as well as Privileged Remote Access Versions 23.2.1 and 23.2.2,” Elliott said, both of which were released in the last three months.

The company remediated the bug “immediately”, he said. 

“A patch is available and has been automatically deployed to our cloud customers, and to all on-premises customers who participate in our automatic critical update process. 

“All impacted on-premises customers have been proactively contacted to install the available patch immediately.”

The bug has a CVSS score of 10, and according to the advisory posted by Krebs, it’s a command injection vulnerability that gives unauthenticated remote attackers the ability to “execute underlying operating system commands within the context of the site user”.

The company said it discovered the vulnerability during “standard code audits and penetration tests”.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Tasmanian gov agencies impacted by cyber attack

Tasmanian gov agencies impacted by cyber attack

Australian chief at US defence contractor L3Harris sold exploits to Russia

Australian chief at US defence contractor L3Harris sold exploits to Russia

Vic gov agencies flying blind on server security, audit finds

Vic gov agencies flying blind on server security, audit finds

Home Affairs streamlines risk vetting for gov tech suppliers

Home Affairs streamlines risk vetting for gov tech suppliers

Log In

  |  Forgot your password?