CVE-2023-34362

Confirmed PUBLISHED

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL...

Progress · MOVEit Transfer
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 99.9%

At a Glance

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.

nuclei_scanner ransomware metasploit malware mysql cisa microsoft
CVE Published
Jun 02, 2023
Exploitation Reported
Jun 02, 2023
CVSS
9.8 Critical
EPSS
99.9%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
progress
moveit_transfer

0 to < 2020.0

Affected
progress
moveit_transfer

2020.1

Affected
progress
moveit_transfer

2021.0 to < 2021.0.7

Affected
progress
moveit_transfer

2021.1.0 to < 2021.1.5

Affected
progress
moveit_transfer

2022.0.0 to < 2022.0.5

Affected
progress
moveit_transfer

2022.1.0 to < 2022.1.6

Affected
progress
moveit_transfer

2023.0.0 to < 2023.0.2

Affected
progress
moveit_cloud

14.1.0.0 to <= 14.1.6.97

Affected
progress
moveit_cloud

14.0.5.45

Affected
n/a
n/a

n/a

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.