Threat Intelligence / CVE / CVE-2024-12356
CVE-2024-12356
CISA KEVA critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-77
Threats tracking this CVE
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-12356
- https://www.beyondtrust.com/trust-center/security-advisories/bt24-10
- https://www.cve.org/CVERecord?id=CVE-2024-12356
- https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12356
Full detection coverage & IOCs for threats exploiting CVE-2024-12356 are available via the Threadlinqs MCP server (Purple tier). View plans →