← back
CVE-2024-5806criticalobserved exploitationCWE-287

MOVEit Transfer Authentication Bypass Vulnerability

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.1epss 81%
from disclosure to weapon0 days
Published on NVDJun 25
1st PoCJun 24
metasploitJun 25
VulnCheckJun 25
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.