CVE-2023-34362: Progress MOVEit Transfer
EPSS99.9%No. 109 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV9
Same product1
| Field | Value |
|---|---|
| Vendor | Progress |
| Product | MOVEit Transfer |
| Name | Progress MOVEit Transfer SQL Injection Vulnerability |
| Added to KEV | 2023-06-02 |
| US federal due date | 2023-06-23 |
| Ransomware use | Known |
| CWE | CWE-89 |
CISA description
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Progress MOVEit Transfer vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-02.