CVE-2024-40595
CVE-2024-40595: Authentication bypass vulnerability in One Identity Safeguard for Privileged Sessions (SPS) allows man-in-the-middle (MitM) attacks. This vulnerability affects On-Premise versions before 7.5.1 and LTS versions before 7.0.5.1. Attackers can intercept cleartext RDP data to gain unauthorized access to privileged sessions. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a potential risk, especially given the CWE-319 classification for cleartext transmission of sensitive information. Organizations using affected versions of One Identity Safeguard SPS should prioritize upgrading to the patched versions to mitigate the security risk. Successful exploitation enables attackers to bypass authentication, potentially leading to full control over privileged sessions and compromised systems. The presence of the "In The Wild" tag underscores the urgency for remediation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.