PT-2024-5295 · Progress · Progress Moveit Transfer

·

CVE-2024-6576

·

Published

2024-07-29

·

Updated

2025-08-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress MOVEit Transfer versions 2023.0.0 through 2023.0.11 Progress MOVEit Transfer versions 2023.1.0 through 2023.1.6 Progress MOVEit Transfer versions 2024.0.0 through 2024.0.2
Description The issue is related to improper authentication in the SFTP module of Progress MOVEit Transfer, which can lead to privilege escalation. An attacker can exploit this issue to bypass the authentication process and elevate their privileges.
Recommendations For Progress MOVEit Transfer versions 2023.0.0 through 2023.0.11, update to version 2023.0.12 or later. For Progress MOVEit Transfer versions 2023.1.0 through 2023.1.6, update to version 2023.1.7 or later. For Progress MOVEit Transfer versions 2024.0.0 through 2024.0.2, update to version 2024.0.3 or later.

Fix

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05920
CVE-2024-6576

Affected Products

Progress Moveit Transfer