CVE-2024-5806 is a critical Improper Authentication vulnerability in the SFTP module of Progress MOVEit Transfer, affecting versions 2023.0.0 through 2023.0.10, 2023.1.0 through 2023.1.5, and 2024.0.0 through 2024.0.1. This flaw allows for authentication bypass, enabling unauthorized access. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. A Metasploit module for arbitrary file read exists, and the vulnerability has garnered significant community attention and media coverage, indicating active exploitation attempts are likely.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2023.0.0, < 2023.0.11CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2023.1.0, < 2023.1.6CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
2024.0.0CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:2024.0.0:*:*:*:*:*:*:* | ||
>= 2024.0.0, < 2024.0.2CPE match | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.