CVE-2025-13147: External Service Interaction (DNS)
Published Nov 19, 2025
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4.
Affected Software
3 affected components
Progress MOVEit Transfer<2024.1.8, >=2025.0.0<2025.0.4
Progress MOVEit Transfer<2024.1.8
Progress MOVEit Transfer>=2025.0.0<2025.0.4
Event History
Nov 19, 2025
CVE Published
via MITRE·08:45 PM
Data Sourced
via MITRE·08:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13147?
CVE-2025-13147 is rated as a critical severity vulnerability due to the potential for Server-Side Request Forgery.
2
What versions are affected by CVE-2025-13147?
CVE-2025-13147 affects Progress MOVEit Transfer versions prior to 2024.1.8 and from 2025.0.0 up to but not including 2025.0.4.
3
How do I fix CVE-2025-13147?
To address CVE-2025-13147, upgrade Progress MOVEit Transfer to version 2024.1.8 or upgrade to 2025.0.4 or later.
4
What type of vulnerability is CVE-2025-13147?
CVE-2025-13147 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
5
Why is CVE-2025-13147 a concern for users of MOVEit Transfer?
CVE-2025-13147 is concerning because it can allow attackers to make unauthorized requests and potentially access sensitive information from the server.