CyberzSOC

Publication detail
← Back to advisories & guidance

2024-063: Critical Vulnerability in MOVEit Transfer ↗ source

June 27, 2024 CERT-EU Advisory

Summary

This vulnerability allows attackers to bypass authentication and access sensitive data [1]. The vulnerability is actively being exploited, and there is an available proof of concept (PoC) The vulnerability CVE-2024-5806, with a CVSS score of 9,1, is an Improper Authentication vulnerability that can lead to Authentication Bypass. Researchers have identified at least two attack scenarios for exploiting this vulnerability. First, the vulnerability allows the use of a null string as a public encryption key during authentication. This can enable unauthorised access, allowing attackers to log in as an existing Second, attackers can obtain cryptographic hashes that mask user passwords.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-5806 9.1 Critical Progress MOVEit Transfer Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.