Vulnerability Description
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Moveit Transfer | < 2020.1.11 |
Related Weaknesses (CWE)
References
- https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-JulRelease NotesVendor Advisory
- https://www.progress.com/moveitProduct
- https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-JulRelease NotesVendor Advisory
- https://www.progress.com/moveitProduct
FAQ
What is CVE-2023-36933?
CVE-2023-36933 is a vulnerability with a CVSS score of 7.5 (HIGH). In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in ...
How severe is CVE-2023-36933?
CVE-2023-36933 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36933?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Moveit Transfer.