CVE-2024-5806

Published Jun 25, 2024

Last updated 4 months ago

Awaiting analysis

Description

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

Insights

Analysis from the Intruder Security Team Published Oct 15, 2024

This vulnerability affects Progress MOVEit servers utilising SFTP and allows attackers to log in as any user if they can successfully guess their username. Depending on how MOVEit is configured, this could be a trivial step.

More information is available in our blog post here.

Risk scores

CVSS 3.1

Secondary
9.1
5.2
3.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CRITICAL

Weaknesses

CWE-287

Source

security@progress.com