CVE-2023-36933

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/07/2023
Last modified:
12/07/2023

Description

In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* 2020.1.11 (excluding)
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* 2021.0 (including) 2021.0.9 (excluding)
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* 2021.1.0 (including) 2021.1.7 (excluding)
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* 2022.0.0 (including) 2022.0.7 (excluding)
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* 2022.1.0 (including) 2022.1.8 (excluding)
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* 2023.0.0 (including) 2023.0.4 (excluding)