QID 378634

Date Published: 2023-07-06

QID 378634: Progress MOVEit Transfer Denial of Service (DoS) Vulnerability

In Progress MOVEit Transfer versions released before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method which results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.

Affected Versions:
Progress MOVEit Transfer versions prior to 2021.0.9 (13.0.9)
Progress MOVEit Transfer versions prior to 2021.1.7 (13.1.7)
Progress MOVEit Transfer versions prior to 2022.0.7 (14.0.7)
Progress MOVEit Transfer versions prior to 2022.1.8 (14.1.8)
Progress MOVEit Transfer versions prior to 2023.0.4 (15.0.4)

QID Detection Logic: (Authenticated)
This QID checks file version of MOVEit.DMZ.ClassLib.dll to identify the vulnerable versions of the product MOVEit Transfer.

QID Detection Logic: (Unauthenticated)
This QID checks vulnerable version of MOVEit Transfer by sending a HTTP GET request to '/moveitisapi/moveitisapi.dll?action=capa' endpoint and checking the X-MOVEitISAPI-Version header.

Successful exploitation of the vulnerability may allow a remote attacker to terminate MOVEit Transfer application unexpectedly.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to the article Article 000236387 for more information regarding the vulnerability and its related patches.

    CVEs related to QID 378634

    Software Advisories
    Advisory ID Software Component Link
    000236387 URL Logo community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023