VDB
CVE-2024-5805
CVE-2024-5805
PUBLISHED
Es bestehen mehrere Schwachstellen in der Progress Software MOVEit. Diese Fehler bestehen im SFTP-Modul aufgrund einer nicht ordnungsgemäßen Authentifizierung. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um die Sicherheitsmaßnahmen zu umgehen.
EPSS 0.65% · 71.2th percentile
Risk Scores
EPSS Score
0.65%
71.2th percentile
Timeline
- Jun 25, 2024 CVE Published
- Jun 26, 2024 EPSS Score
- Jul 18, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Sep 1, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 16, 2024 EPSS Score
- Nov 8, 2024 EPSS Score
- Nov 12, 2024 PoC Published
- Dec 24, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1457.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1457 advisory
- https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806 advisory
- https://community.progress.com/s/article/MOVEit-Gateway-Critical-Security-Alert-Bulletin-June-2024-CVE-2024-5805 advisory
- https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/ advisory
- https://www.borncity.com/blog/2024/06/26/progress-moveit-transfer-angriffe-auf-schwachstelle-cve-2024-5806/ advisory
- https://www.tenable.com/blog/cve-2024-5806-progress-moveit-transfer-authentication-bypass-vulnerability advisory