PT-2024-5295 · Progress · Progress Moveit Transfer

Discovered Internally

·

Published

2024-07-29

·

Updated

2025-08-01

·

CVE-2024-6576

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress MOVEit Transfer versions 2023.0.0 through 2023.0.11 Progress MOVEit Transfer versions 2023.1.0 through 2023.1.6 Progress MOVEit Transfer versions 2024.0.0 through 2024.0.2
Description The issue is related to improper authentication in the SFTP module of Progress MOVEit Transfer, which can lead to privilege escalation. An attacker can exploit this issue to bypass the authentication process and elevate their privileges.
Recommendations For Progress MOVEit Transfer versions 2023.0.0 through 2023.0.11, update to version 2023.0.12 or later. For Progress MOVEit Transfer versions 2023.1.0 through 2023.1.6, update to version 2023.1.7 or later. For Progress MOVEit Transfer versions 2024.0.0 through 2024.0.2, update to version 2024.0.3 or later.

Fix

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-05920
CVE-2024-6576

Affected Products

Progress Moveit Transfer