CVE-2024-5806

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:2024.0.0:*:*:*:*:*:*:*

History

16 Jan 2025, 16:57

Type Values Removed Values Added
CPE cpe:2.3:a:progress:moveit_transfer:2024.0.1:*:*:*:*:*:*:*

16 Jan 2025, 16:48

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Progress
Progress moveit Transfer
References () https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806 - () https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806 - Vendor Advisory
References () https://www.progress.com/moveit - () https://www.progress.com/moveit - Product
CPE cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:2024.0.0:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:2024.0.1:*:*:*:*:*:*:*

21 Nov 2024, 09:48

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de autenticación incorrecta en Progress MOVEit Transfer (módulo SFTP) puede provocar una omisión de autenticación. Este problema afecta a MOVEit Transfer: desde 2023.0.0 antes de 2023.0.11, desde 2023.1.0 antes de 2023.1.6, desde 2024.0.0 antes de 2024.0.2.
References () https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806 - () https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806 -
References () https://www.progress.com/moveit - () https://www.progress.com/moveit -

26 Jun 2024, 00:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.4
v2 : unknown
v3 : 9.1
Summary (en) Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass in limited scenarios.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2. (en) Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

25 Jun 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-25 15:15

Updated : 2025-01-16 16:57


NVD link : CVE-2024-5806

Mitre link : CVE-2024-5806

CVE.ORG link : CVE-2024-5806


JSON object : View

Products Affected

progress

  • moveit_transfer
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo