CVE-2024-2291
Estado: AnalizadaMedia (4.3)—
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-778
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-2291",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-2291",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-03-20T20:09:08.372929Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@progress.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@progress.com",
"affectedData": [
{
"vendor": "Progress Software",
"product": "MOVEit Transfer",
"versions": [
{
"status": "affected",
"version": "2022.0.0 (14.0.0)",
"lessThan": "2022.0.11 (14.0.11)",
"versionType": "semver"
},
{
"status": "affected",
"version": "2022.1.0 (14.1.0)",
"lessThan": "2022.1.12 (14.1.12)",
"versionType": "semver"
},
{
"status": "affected",
"version": "2023.0.0 (15.0.0)",
"lessThan": "2023.0.9 (15.0.9)",
"versionType": "semver"
},
{
"status": "affected",
"version": "2023.1.0 (15.1.0)",
"lessThan": "2023.1.4 (15.1.4)",
"versionType": "semver"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-03-20T15:15:08.010",
"references": [
{
"url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024",
"tags": [
"Vendor Advisory"
],
"source": "security@progress.com"
},
{
"url": "https://www.progress.com/moveit",
"tags": [
"Product"
],
"source": "security@progress.com"
},
{
"url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.progress.com/moveit",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@progress.com",
"description": [
{
"lang": "en",
"value": "CWE-778"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\nIn Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly."
},
{
"lang": "es",
"value": "Se ha descubierto una vulnerabilidad de omisión de registro en las versiones de MOVEit Transfer publicadas antes de 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4). Un usuario autenticado podría manipular una solicitud para omitir el mecanismo de registro dentro de la aplicación web, lo que da como resultado que la actividad del usuario no se registre correctamente."
}
],
"lastModified": "2026-06-17T07:24:15.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A33F43C2-F905-43C3-A9D4-671BEE079C68",
"versionEndExcluding": "2022.0.11"
},
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BD95EE0-833F-42E9-BCCA-EC4089AB6E62",
"versionEndExcluding": "2022.1.12",
"versionStartIncluding": "2022.1.0"
},
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D682546D-079E-431A-BFA9-DEF714BA364A",
"versionEndExcluding": "2023.0.9",
"versionStartIncluding": "2023.0.0"
},
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E72FDB08-3760-4472-A60C-BDDD51B25708",
"versionEndExcluding": "2023.1.4",
"versionStartIncluding": "2023.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@progress.com"
}