« Volver al listado

CVE-2024-2291

Estado: AnalizadaMedia (4.3)—

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2291",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2291",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-20T20:09:08.372929Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@progress.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@progress.com",
      "affectedData": [
        {
          "vendor": "Progress Software",
          "product": "MOVEit Transfer",
          "versions": [
            {
              "status": "affected",
              "version": "2022.0.0 (14.0.0)",
              "lessThan": "2022.0.11 (14.0.11)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2022.1.0 (14.1.0)",
              "lessThan": "2022.1.12 (14.1.12)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2023.0.0 (15.0.0)",
              "lessThan": "2023.0.9 (15.0.9)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2023.1.0 (15.1.0)",
              "lessThan": "2023.1.4 (15.1.4)",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-03-20T15:15:08.010",
  "references": [
    {
      "url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://www.progress.com/moveit",
      "tags": [
        "Product"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.progress.com/moveit",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@progress.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-778"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nIn Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto una vulnerabilidad de omisión de registro en las versiones de MOVEit Transfer publicadas antes de 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4). Un usuario autenticado podría manipular una solicitud para omitir el mecanismo de registro dentro de la aplicación web, lo que da como resultado que la actividad del usuario no se registre correctamente."
    }
  ],
  "lastModified": "2026-06-17T07:24:15.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A33F43C2-F905-43C3-A9D4-671BEE079C68",
              "versionEndExcluding": "2022.0.11"
            },
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BD95EE0-833F-42E9-BCCA-EC4089AB6E62",
              "versionEndExcluding": "2022.1.12",
              "versionStartIncluding": "2022.1.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D682546D-079E-431A-BFA9-DEF714BA364A",
              "versionEndExcluding": "2023.0.9",
              "versionStartIncluding": "2023.0.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E72FDB08-3760-4472-A60C-BDDD51B25708",
              "versionEndExcluding": "2023.1.4",
              "versionStartIncluding": "2023.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@progress.com"
}