CVE-2024-6576: MOVEit Transfer Privilege Escalation Vulnerability
Published Jul 29, 2024
·Updated
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.
Affected Software
4 affected components
Progress MOVEit Transfer>2023.0.0, <2023.0.12, >2023.1.0, <2023.1.7, >2024.0.0, <2024.0.3
Progress MOVEit Transfer>=2023.0.0<2023.0.12
Progress MOVEit Transfer>=2023.1.0<2023.1.7
Progress MOVEit Transfer>=2024.0.0<2024.0.3
Event History
Jul 29, 2024
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6576?
CVE-2024-6576 is categorized as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2024-6576?
To fix CVE-2024-6576, upgrade Progress MOVEit Transfer to versions 2023.0.12, 2023.1.7, or 2024.0.3 or later.
3
Which versions of Progress MOVEit Transfer are affected by CVE-2024-6576?
CVE-2024-6576 affects Progress MOVEit Transfer versions before 2023.0.12, before 2023.1.7, and before 2024.0.3.
4
What type of vulnerability is CVE-2024-6576?
CVE-2024-6576 is classified as an Improper Authentication vulnerability.
5
What could be the impact of exploiting CVE-2024-6576?
Exploiting CVE-2024-6576 could lead to unauthorized privilege escalation within the affected system.