MOVEit Transfer Authentication Bypass Vulnerability
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.1epss 81%
from disclosure to weapon0 days
Published on NVDJun 25
1st PoCJun 24
metasploitJun 25
VulnCheckJun 25
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Progress · MOVEit Transferpublic PoCs found — 4
githubgithub.com/watchtowrlabs/watchTowr-vs-progress-moveit_CVE-2024-5806★ 45githubgithub.com/sec13b/CVE-2024-5806★ 0vulncheckvulncheck.com/xdb/0c37c1c99a26unverifiedvulncheckvulncheck.com/xdb/a9343dc7c981unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.