Privileged Remote Access Authentication Bypass
Vulnerability Description
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0217
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Paul Szabo of the University of Sydney
More from BeyondTrust
View All →Affected Vendor
BeyondTrust
View all reports →