CRITICAL🇵🇱 Wersja polska

CVE-2024-5806

CVSS 9.1v3.1pub. 2024-06-25upd. 2025-01-16

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

🤖 AI Analysis
How it works

The flaw lies in the SFTP module of MOVEit Transfer software and consists of an improper implementation of the authentication process. An attacker remotely, without possessing any credentials or user interaction, can conduct a network-based attack (AV:N, PR:N, UI:N) and effectively bypass access control mechanisms. The detailed technical mechanism was not disclosed in the manufacturer's public description.

Impact

Successful exploitation of the vulnerability allows an attacker to gain unauthorized access to the system with the ability to read and modify stored data (C:H, I:H). This could result in the leakage of sensitive files transmitted by the organization or their unauthorized manipulation.

Mitigation & patch

Progress MOVEit Transfer must be immediately updated to versions that eliminate the vulnerability: 2023.0.11 or newer (for the 2023.0.x branch), 2023.1.6 or newer (for the 2023.1.x branch), 2024.0.2 or newer (for the 2024.0.x branch). Detailed instructions are available in the manufacturer's security bulletin at the address indicated in the references.

Who is affected

Progress MOVEit Transfer in versions: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2 — affects only the SFTP module.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Progress Moveit Transfer

    APP
    Progress
    2024.0.02023.0.0 – 2023.0.11 (excl.)2023.1.0 – 2023.1.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-34362CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w Progress MOVEit Transfer – nieautoryzowany dostęp do bazy danych

CVE-2023-36934CRITICAL9.1PL ✓same product

SQL Injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych

CVE-2023-35708CRITICAL9.8PL ✓same product

SQL injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych

CVE-2023-35036CRITICAL9.1PL ✓same product

SQL Injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych

CVE-2021-38159CRITICAL9.8PL ✓same product

SQL Injection w Progress MOVEit Transfer — nieautoryzowany dostęp do bazy danych