Critical - CVSS 9.8
Known Ransomware Use
Added 6/2/2023

Progress MOVEit Transfer SQL Injection Vulnerability

CVE-2023-34362
Action was due by: 6/23/2023
CISA Known Exploited Vulnerability

This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.

Overview

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Vendor

Progress

Product

MOVEit Transfer

Category

Software
Technical Details

Affected Versions

See vendor advisory

Technical Description

This vulnerability was identified in MOVEit Transfer by Progress. Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Exploitability

High - Known ransomware exploitation

Impact

Complete system compromise possible

Additional Notes

This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.; https://nvd.nist.gov/vuln/detail/CVE-2023-34362

Required Action (CISA)

Apply updates per vendor instructions.

Due Date: 6/23/2023