Overview
- Description
- An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information.
- Source
- cve@mitre.org
- NVD status
- Awaiting Analysis
Risk scores
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 3.6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
Weaknesses
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-319
Social media
- Hype score
- Not currently trending
One Identity の脆弱性 CVE-2024-40595 が FIX:RDP 認証バイパスの恐れ https://t.co/kH01dHO3qH #OneIdentity #RDP #SPS
@iototsecnews
1 Nov 2024
116 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-40595 An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows ma… https://t.co/mwHCDSpMiE
@CVEnew
24 Oct 2024
263 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes