CVE-2025-5309

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
BTCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
beyondtrustprivileged_remote_access
24.2.2 ≤
𝑥
≤ 24.2.4
beyondtrustprivileged_remote_access
24.3.1 ≤
𝑥
< 24.3.4
beyondtrustprivileged_remote_access
25.1.1
beyondtrustremote_support
24.2.2 ≤
𝑥
≤ 24.2.4
beyondtrustremote_support
24.3.1 ≤
𝑥
< 24.3.4
beyondtrustremote_support
25.1.1
𝑥
= Vulnerable software versions