« Volver al listado

CVE-2024-0396

Estado: ModificadaAlta (7.1)—

In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0396",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0396",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-23T20:58:50.772488Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@progress.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@progress.com",
      "affectedData": [
        {
          "vendor": "Progress Software Corporation",
          "product": "MOVEit Transfer",
          "versions": [
            {
              "status": "affected",
              "version": "2022.0.0 (14.0.0)",
              "lessThan": "2022.0.10 (14.0.10)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2022.1.0 (14.1.0)",
              "lessThan": "2022.1.11 (14.1.11)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2023.0.0 (15.0.0)",
              "lessThan": "2023.0.8 (15.0.8)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2023.1.0 (15.1.0)",
              "lessThan": "2023.1.3 (15.1.3)",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-01-17T16:15:46.623",
  "references": [
    {
      "url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-January-2024",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://www.progress.com/moveit",
      "tags": [
        "Product"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-January-2024",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.progress.com/moveit",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@progress.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nIn Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered.  An authenticated user can manipulate a parameter in an HTTPS transaction.  The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.\n\n"
    },
    {
      "lang": "es",
      "value": "En las versiones de Progress MOVEit Transfer lanzadas antes de 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), se descubrió un problema de validación de entrada. Un usuario autenticado puede manipular un parámetro en una transacción HTTPS. La transacción modificada podría provocar errores computacionales dentro de MOVEit Transfer y potencialmente resultar en una denegación de servicio."
    }
  ],
  "lastModified": "2026-06-17T06:53:24.743",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B392A9C3-723E-48B9-83F9-C020A3FA4A88",
              "versionEndExcluding": "2022.0.10"
            },
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4327F71-29F5-42BE-BB63-55912ACD82F7",
              "versionEndExcluding": "2022.1.11",
              "versionStartIncluding": "2022.1.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D751E70-646C-4CB4-92A5-A53EB0505025",
              "versionEndExcluding": "2023.0.8",
              "versionStartIncluding": "2023.0.1"
            },
            {
              "criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E05648FB-598C-4884-BDFC-6C16C7152016",
              "versionEndExcluding": "2023.1.3",
              "versionStartIncluding": "2023.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@progress.com"
}