Vulnerability record · CVE-2024-5806 · published 25 June 2024
CVE-2024-5806: Progress MOVEit Transfer SFTP authentication bypass
Progress · Moveit Transfer
Progress MOVEit Transfer contains an improper authentication flaw in its SFTP module that allows authentication bypass. The affected versions are 2023.0.0 before 2023.0.11, 2023.1.0 before 2023.1.6, and 2024.0.0 before 2024.0.2. Because MOVEit Transfer is widely used for managed file transfers, a bypass of this kind exposes sensitive data flows and is rated critical by NVD.
Description
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction required, and a very high EPSS score make this a top remediation priority despite no KEV listing.
What it is
Progress MOVEit Transfer contains an improper authentication flaw in its SFTP module that allows authentication bypass. The affected versions are 2023.0.0 before 2023.0.11, 2023.1.0 before 2023.1.6, and 2024.0.0 before 2024.0.2. Because MOVEit Transfer is widely used for managed file transfers, a bypass of this kind exposes sensitive data flows and is rated critical by NVD.
Impact
An attacker can bypass authentication and gain unauthorized access to the SFTP service, with the CVSS vector indicating high confidentiality, integrity, and availability impact. In practice this means access to transferred files and the ability to act within the SFTP context without valid credentials.
Attack surface
The flaw is reachable over the network through the SFTP module, with no privileges or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed MOVEit Transfer SFTP endpoint is in scope.
Exploitation
EPSS is very high (0.81474, 99.6th percentile), indicating elevated likelihood of exploitation activity. The record is not listed in CISA KEV and the references carry only Vendor Advisory and Product tags, so no confirmed in-the-wild exploitation is documented here.
What to do
- Upgrade MOVEit Transfer to 2023.0.11, 2023.1.6, 2024.0.2 or later as directed by the Progress advisory.
- If immediate patching is not possible, restrict or disable external access to the SFTP service and limit it to trusted networks.
- Review Progress guidance for any interim configuration or mitigation steps specific to the SFTP module.
- Audit SFTP accounts and access logs for unexpected or unauthorized sessions.
- Apply network segmentation so MOVEit Transfer is not directly reachable from untrusted networks.
Detection
- Monitor SFTP authentication logs for successful logins that lack a corresponding valid credential or expected source.
- Alert on anomalous SFTP sessions, including unusual source IPs, off-hours access, or atypical file transfers.
- Correlate MOVEit Transfer SFTP activity with identity provider or directory authentication events to find sessions with no matching authentication.
- Track for exploitation attempts against the SFTP service and review Progress advisory indicators if published.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-5806 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5806), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.