Vulnerability Description
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beyondtrust | Privileged Remote Access | >= 22.2.1, < 22.3.3 |
Related Weaknesses (CWE)
References
- https://www.compass-security.com/fileadmin/Research/Advisories/2023_03_CSNC-2022Third Party Advisory
- http://seclists.org/fulldisclosure/2025/May/1
- https://www.compass-security.com/fileadmin/Research/Advisories/2023_03_CSNC-2022Third Party Advisory
FAQ
What is CVE-2023-23632?
CVE-2023-23632 is a vulnerability with a CVSS score of 7.8 (HIGH). BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump ...
How severe is CVE-2023-23632?
CVE-2023-23632 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23632?
Check the references section above for vendor advisories and patch information. Affected products include: Beyondtrust Privileged Remote Access.