S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-31589 Scanner

CVE-2021-31589 scanner - Cross-Site Scripting (XSS) vulnerability in BeyondTrust Remote Support

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-31589
6.1
CVSS

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

BeyondTrust Secure Remote Access is a popular software solution utilized by individuals and organizations alike for remote support and access purposes. With its advanced features and functionality, it has become a go-to choice for IT administrators, helpdesk teams, and service desk agents. The software enables support technicians to connect to remote computers, servers, and mobile devices from anywhere in the world to provide assistance and troubleshoot issues.

However, BeyondTrust Secure Remote Access Base Software version 6.0.1, and older has been found to contain a security vulnerability labeled CVE-2021-31589. This cross-site scripting (XSS) vulnerability is a type of attack that allows an attacker to inject malicious code into a web page, which is then executed by the victim's browser.

Exploitation of this vulnerability could lead to various malicious activities, including the theft of sensitive user data, modification of web pages, and execution of arbitrary code on the victim's computer. By using this vulnerability, an attacker can gain unauthorized access to a remote machine or device, allowing them to execute various malicious actions undetected.

Thanks to the pro features of the s4e.io platform, individuals and organizations can quickly and easily learn about vulnerabilities in their digital assets. The platform provides comprehensive information on software vulnerabilities, including alerts on new threats, vulnerability descriptions, risk ratings, and recommended mitigation strategies. With s4e.io, users can stay informed and proactive in protecting their assets from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, BeyondTrust Secure Remote Access users are advised to take the following precautions:

  • Upgrade to the latest version of the software, which contains a fix for this vulnerability.
  • Implement a web application firewall (WAF) to block any malicious traffic attempting to exploit this vulnerability.
  • Educate employees and users who interact with the software on safe browsing practices and avoiding suspicious links or downloads.
  • Use access controls to limit the number of users and privilege levels for users with access to the software.
  • Implement two-factor authentication to add an extra layer of security to the remote access process.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.