CVE-2024-40595: Oneidentity Safeguard For Privileged Sessions

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information.

Affected products

  • Oneidentity Safeguard For Privileged Sessions: before 7.5.1 (fixed in 7.5.1); before 7.0.5.1_lts (fixed in 7.0.5.1_lts)

Published 2024-10-24. Last modified 2026-06-17.