Skip to main content

Vendor archive

beyondtrust CVEs

Beta · best-effort

36 CVEs tagged to vendor beyondtrust5 Critical, 21 High, 8 Medium, 2 Low, 0 Unrated.

CVE-2025-2297

Published Jul 28, 2025

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certa…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0217

Published May 5, 2025

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details o…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0889

Published Feb 26, 2025

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9110

Published Oct 30, 2024

A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5813

Published Jun 11, 2024

A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the ser…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5812

Published Jun 11, 2024

A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a s…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4220

Published Jun 4, 2024

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4219

Published Jun 4, 2024

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49944

Published Dec 25, 2023

The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12612

Published Dec 12, 2023

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86)…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2