BeyondTrust - Secure Remote Access and Privileged Access Management

Advisory ID: BT24-08

  • CVSSv3 Score: 5.9

  • Severity: Medium

  • Issue Date: 2024-06-11

  • CVE: CVE-2024-5813

Summary

A medium severity vulnerability in BeyondInsight Password Safe has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.

Affected Versions

Product

Version

BeyondInsight Password Safe

23.3 versions before the .929 hotfix

Fixed Versions

Product

Version

BeyondInsight Password Safe

24.1 and later

BeyondInsight Password Safe

23.3.0.929 and later

Acknowledgements

BeyondTrust would like to acknowledge Christian Dölling for reporting this issue.