{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-12356",
  "revision": 1,
  "title": "BeyondTrust remote access — unauthenticated command injection",
  "summary": "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) let an unauthenticated attacker inject commands that run as the site user, which is enough to take the appliance brokering privileged sessions.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.87901,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2024-12-19",
    "prerequisites": "Network access to the appliance; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply the BeyondTrust advisory fix now; exploit code is public, so treat an exposed appliance as compromised and rotate what it brokered.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-12356",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-12356",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-12356",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12356",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt24-10"
    },
    {
      "type": "exploit",
      "url": "https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis"
    },
    {
      "type": "writeup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-12356"
    }
  ],
  "published_at": "2024-12-17T05:15:06.413Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "beyondtrust",
    "remote-support",
    "command-injection",
    "kev"
  ]
}
