MOVEit Transfer Security Update – 26 June 2024

MOVEit Transfer has released security updates to address a critical vulnerability across multiple versions of Progress MOVEit Transfer.

The addressed vulnerability could allow the remote attacker to bypass authentication because of inadequate authentication measures.

Progress MOVEit Transfer Authentication Bypass Vulnerability (CVE-2024-5806):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

Affected versions:

  • MOVEit Transfer from 2023.0.0 before 2023.0.11.
  • MOVEit Transfer from 2023.1.0 before 2023.1.6.
  • MOVEit Transfer from 2024.0.0 before 2024.0.2.
Vulnerabilities

CVE-2024-5806

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

MOVEit Transfer Security Update

References