7.5

CVE-2023-36933

In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.

Data is provided by the National Vulnerability Database (NVD)
ProgressMoveit Transfer Version < 2020.1.11
ProgressMoveit Transfer Version >= 2021.0 < 2021.0.9
ProgressMoveit Transfer Version >= 2021.1.0 < 2021.1.7
ProgressMoveit Transfer Version >= 2022.0.0 < 2022.0.7
ProgressMoveit Transfer Version >= 2022.1.0 < 2022.1.8
ProgressMoveit Transfer Version >= 2023.0.0 < 2023.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 19.16% 0.952
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.