Man-in-the-Middle Attack Allows Access to Privileged Sessions
CVE-2024-40595

Currently unrated

Key Information:

Vendor
CVE Published:
24 October 2024

What is CVE-2024-40595?

An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.