CVE-2024-5806: MOVEit Transfer Authentication Bypass Vulnerability
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5806?
CVE-2024-5806 is identified as a critical vulnerability due to improper authentication leading to authentication bypass.
How do I fix CVE-2024-5806?
To address CVE-2024-5806, upgrade Progress MOVEit Transfer to the latest versions 2023.0.11, 2023.1.6, or 2024.0.2 or later.
Which versions of Progress MOVEit Transfer are affected by CVE-2024-5806?
CVE-2024-5806 affects Progress MOVEit Transfer versions from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, and 2024.0.0 before 2024.0.2.
What are the consequences of CVE-2024-5806 if exploited?
Exploiting CVE-2024-5806 can allow attackers to bypass authentication mechanisms and gain unauthorized access to sensitive data.
Is there a workaround for CVE-2024-5806 while I prepare to upgrade?
Currently, there are no known workarounds for CVE-2024-5806, so immediate upgrading is recommended.