Junglewise Threat Intelligence

CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

CVE-2023-34362 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-02

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

A SQL injection vulnerability in Progress MOVEit Transfer allows unauthenticated attackers to gain unauthorized access to the application's database. Attackers can infer database structure, retrieve contents, and execute statements to alter or delete data across MySQL, Microsoft SQL Server, and Azure SQL environments.

Affected products

  • Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1)
  • Progress MOVEit Cloud versions up to (excluding) 14.0.5.45, 14.1.6.97, 15.0.2.39

Timeline

  • 2023-05-31: advisory: Vendor advisory published by Progress
  • 2023-05-01: exploited: Exploitation in the wild began in May 2023
  • 2023-06-02: disclosed: CVE published and added to CISA KEV catalog

Related threats