MOVEit GatewayおよびMOVEit Transferの脆弱性
2024年6月27日
著者 Lauren Farrell
On June 25, 2024, Progress Software, the parent company of the MOVEit software suite, officially released details for two critical vulnerabilities identified in MOVEit Gateway and MOVEit Transfer, CVE-2024-5805 and CVE-2024-5806 respectively.
MOVEit Transfer is a managed file transfer solution that supports the exchange of files and data between servers, systems and applications within and between organizations. MOVEit Gateway is a proxy service that works in conjunction with MOVEit Transfer and allows hosting the MOVEit Transfer service on internal network while placing the Gateway within a DMZ to facilitate external access.
Both these vulnerabilities in MOVEit Gateway and MOVEit Transfer stem from improper authentication as implemented in the SFTP module which can lead to Authentication Bypass, in-turn leading to unauthorized access. CVE-2024-5805 was assigned a Base CVSS score of 9.1 earning a critical severity rating while CVE-2024-5806 was initially assigned a CVSS score of 7.4. On June 26, 2024, Progress Software updated their description for CVE-2024-5806 stating “A newly identified vulnerability in a third-party component used in MOVEit Transfer elevates the risk of the original issue mentioned above if left unpatched.” Consequently, the CVSS score was elevated to a matching critical score of 9.1.
The newly identified vulnerability is likely in reference to a vulnerability found in IPWorks SSH, a server library utilized by the MOVEit software suite to handle key pair authentication and other lower-level SSH operations. A writeup from WatchTowr Labs states that the original identified vulnerability in MOVEit Transfer, “arises from the interplay between MOVEit and IPWorks SSH, and a failure to handle an error condition.”
The following versions of MOVEit Transfer are vulnerable to CVE-2024-5806:
- From 2023.0.0 before 2023.0.11
- From 2023.1.0 before 2023.1.6
- From 2024.0.0 before 2024.0.2
- 2024.0.0
- MOVEit Gateway Critical Security Alert Bulletin
- MOVEit Transfer Critical Security Alert Bulletin
- Vulnerability Details : CVE-2024-5805
- Vulnerability Details : CVE-2024-5806
- Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806)
- MOVEit Transfer: Auth bypass and a look at exposure
- MOVEit Exposure Tracker
- X: The Shadowserver Foundation
- Authentication Bypasses in MOVEit Transfer and MOVEit Gateway
迫り来る脅威を知る。 次の脅威を止める。
こちらから無料の脅威アラート速報サービスに登録してください。
あなたの組織にふさわしいサイバー犯罪の防壁
当社のセキュリティ チームによるカスタム デモンストレーションにご登録ください。当社が優秀な人材と最も完全な脅威インテリジェンスのコレクションを結集して、驚くべきレベルの安心感を提供する方法を説明します。