CVE-2023-36933 is a denial-of-service vulnerability affecting Progress MOVEit Transfer versions prior to 2021.0.9, 2021.1.7, 2022.0.7, 2022.1.8, and 2023.0.4. An unauthenticated attacker can remotely trigger an unhandled exception, causing the MOVEit Transfer application to terminate unexpectedly. With a CVSS score of 7.5 (High), this vulnerability poses a significant availability risk, as it can disrupt critical file transfer operations. While there is no known public exploit code or active exploitation (not in KEV), the vulnerability has garnered substantial community discussion and media coverage, indicating high awareness and concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.1.11CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.0, < 2021.0.9CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.1.0, < 2021.1.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.0.0, < 2022.0.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.1.0, < 2022.1.8CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.