Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
The flaw lies in the SFTP module of MOVEit Transfer software and consists of an improper implementation of the authentication process. An attacker remotely, without possessing any credentials or user interaction, can conduct a network-based attack (AV:N, PR:N, UI:N) and effectively bypass access control mechanisms. The detailed technical mechanism was not disclosed in the manufacturer's public description.
Successful exploitation of the vulnerability allows an attacker to gain unauthorized access to the system with the ability to read and modify stored data (C:H, I:H). This could result in the leakage of sensitive files transmitted by the organization or their unauthorized manipulation.
Progress MOVEit Transfer must be immediately updated to versions that eliminate the vulnerability: 2023.0.11 or newer (for the 2023.0.x branch), 2023.1.6 or newer (for the 2023.1.x branch), 2024.0.2 or newer (for the 2024.0.x branch). Detailed instructions are available in the manufacturer's security bulletin at the address indicated in the references.
Progress MOVEit Transfer in versions: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2 — affects only the SFTP module.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NProgress Moveit Transfer
APPProgress2024.0.02023.0.0 – 2023.0.11 (excl.)2023.1.0 – 2023.1.6 (excl.)
Related vulnerabilities
SQL Injection w Progress MOVEit Transfer – nieautoryzowany dostęp do bazy danych
SQL Injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych
SQL injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych
SQL Injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych
SQL Injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych