7.1
CVE-2024-0396
- EPSS 0.16%
- Published 17.01.2024 16:15:46
- Last modified 21.11.2024 08:46:29
- Source security@progress.com
- Teams watchlist Login
- Open Login
In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.
Data is provided by the National Vulnerability Database (NVD)
Progress ≫ Moveit Transfer Version < 2022.0.10
Progress ≫ Moveit Transfer Version >= 2022.1.0 < 2022.1.11
Progress ≫ Moveit Transfer Version >= 2023.0.1 < 2023.0.8
Progress ≫ Moveit Transfer Version >= 2023.1.0 < 2023.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.378 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
|
security@progress.com | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.