ID:10181 - Exploit for Improper Authentication in MOVEit Transfer - CVE-2024-5806

 
Main Vulnerability Database Exploits ID:10181 - Exploit for Improper Authentication in MOVEit Transfer - CVE-2024-5806

ID:10181 - Exploit for Improper Authentication in MOVEit Transfer - CVE-2024-5806

Published: July 5, 2024


Vulnerability identifier: #VU93368
Vulnerability risk: Critical
CVE-ID: CVE-2024-5806
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
MOVEit Transfer

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error within the SFTP module in guestaccess.aspx. A remote non-authenticated attacker can send a specially crafted HTTP POST request to bypass authentication process and gain unauthorized access to the system.


Remediation

Install updates from vendor's website.