A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Is CVE-2024-12356 exploited?
Listed in the CISA KEV catalog on 2024-12-19.
Federal remediation due 2024-12-27.
Past that date by 596 days.
EPSS puts exploitation in the next 30 days at 88%.
Public exploit code: packaged in a public tool.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2024-12356
PlainSec has not published a story about this CVE.