PT-2023-7247 · Ipswitch · Moveit Transfer

CVE-2023-6218

·

Publicado

2023-11-20

·

Atualizado

2023-12-09

CVSS v2.0

8.3

Alta

VetorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MOVEit Transfer versions prior to 2022.0.9 (14.0.9) MOVEit Transfer versions prior to 2022.1.10 (14.1.10) MOVEit Transfer versions prior to 2023.0.7 (15.0.7)
Description A privilege escalation path associated with group administrators has been identified, allowing a group administrator to elevate a group member's permissions to the role of an organization administrator. The issue is related to insufficient access control in the software.
Recommendations For versions prior to 2022.0.9 (14.0.9), update to a version newer than 2022.0.9 to resolve the issue. For versions prior to 2022.1.10 (14.1.10), update to a version newer than 2022.1.10 to resolve the issue. For versions prior to 2023.0.7 (15.0.7), update to a version newer than 2023.0.7 to resolve the issue. As a temporary workaround, consider restricting the privileges of group administrators to minimize the risk of exploitation.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08275
CVE-2023-6218

Produtos afetados

Moveit Transfer