PT-2024-1119 · Ipswitch · Moveit Transfer

Hackerone: P-V-P

·

Published

2024-01-17

·

Updated

2024-01-30

·

CVE-2024-0396

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions MOVEit Transfer versions prior to 2022.0.10 (14.0.10) MOVEit Transfer versions prior to 2022.1.11 (14.1.11) MOVEit Transfer versions prior to 2023.0.8 (15.0.8) MOVEit Transfer versions prior to 2023.1.3 (15.1.3)
Description An input validation issue was discovered in MOVEit Transfer, allowing an authenticated user to manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service. The issue is related to incorrect clearance or release of resources in the HTTPS Transaction Handler component.
Recommendations For versions prior to 2022.0.10 (14.0.10), update to a version that includes the fix for this issue. For versions prior to 2022.1.11 (14.1.11), update to a version that includes the fix for this issue. For versions prior to 2023.0.8 (15.0.8), update to a version that includes the fix for this issue. For versions prior to 2023.1.3 (15.1.3), update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the HTTPS transaction handler to minimize the risk of exploitation.

Fix

Improper Resource Release

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-00403
CVE-2024-0396

Affected Products

Moveit Transfer