First published: Tue Jun 25 2024(Updated: )
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress MOVEit Transfer | >=2023.0.0<2023.0.11 | |
Progress MOVEit Transfer | >=2023.1.0<2023.1.6 | |
Progress MOVEit Transfer | =2024.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5806 is identified as a critical vulnerability due to improper authentication leading to authentication bypass.
To address CVE-2024-5806, upgrade Progress MOVEit Transfer to the latest versions 2023.0.11, 2023.1.6, or 2024.0.2 or later.
CVE-2024-5806 affects Progress MOVEit Transfer versions from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, and 2024.0.0 before 2024.0.2.
Exploiting CVE-2024-5806 can allow attackers to bypass authentication mechanisms and gain unauthorized access to sensitive data.
Currently, there are no known workarounds for CVE-2024-5806, so immediate upgrading is recommended.