Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0396


In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.


Published

2024-01-17T16:15:46.623

Last Modified

2024-11-21T08:46:29.587

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress moveit_transfer < 2022.0.10 Yes
Application progress moveit_transfer < 2022.1.11 Yes
Application progress moveit_transfer < 2023.0.8 Yes
Application progress moveit_transfer < 2023.1.3 Yes

References