CVE-2024-4563: The Progress MOVEit Automation Configuration Export Function Uses a Cryptographic Method with Insufficient Bit Length
The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MOVEit Automation configuration export functionto a version that resolves this vulnerability.Fixed in 2024.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4563?
CVE-2024-4563 has a medium severity rating due to the use of an insufficient cryptographic method.
How do I fix CVE-2024-4563?
To fix CVE-2024-4563, upgrade to Progress MOVEit Automation version 2024.0.0 or later.
What systems are affected by CVE-2024-4563?
CVE-2024-4563 affects all versions of Progress MOVEit Automation prior to 2024.0.0.
What type of vulnerability is CVE-2024-4563?
CVE-2024-4563 is a cryptographic vulnerability related to inadequate key length.
What consequences could arise from CVE-2024-4563?
Exploitation of CVE-2024-4563 could lead to weakened data protection and potential unauthorized access.