{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T13:42:29.593","vulnerabilities":[{"cve":{"id":"CVE-2024-0396","sourceIdentifier":"security@progress.com","published":"2024-01-17T16:15:46.623","lastModified":"2026-06-17T06:53:24.743","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"\nIn Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered.  An authenticated user can manipulate a parameter in an HTTPS transaction.  The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.\n\n"},{"lang":"es","value":"En las versiones de Progress MOVEit Transfer lanzadas antes de 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), se descubrió un problema de validación de entrada. Un usuario autenticado puede manipular un parámetro en una transacción HTTPS. La transacción modificada podría provocar errores computacionales dentro de MOVEit Transfer y potencialmente resultar en una denegación de servicio."}],"affected":[{"source":"security@progress.com","affectedData":[{"vendor":"Progress Software Corporation","product":"MOVEit Transfer","defaultStatus":"affected","versions":[{"version":"2022.0.0 (14.0.0)","lessThan":"2022.0.10 (14.0.10)","versionType":"semver","status":"affected"},{"version":"2022.1.0 (14.1.0)","lessThan":"2022.1.11 (14.1.11)","versionType":"semver","status":"affected"},{"version":"2023.0.0 (15.0.0)","lessThan":"2023.0.8 (15.0.8)","versionType":"semver","status":"affected"},{"version":"2023.1.0 (15.1.0)","lessThan":"2023.1.3 (15.1.3)","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@progress.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-23T20:58:50.772488Z","id":"CVE-2024-0396","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@progress.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.0.10","matchCriteriaId":"B392A9C3-723E-48B9-83F9-C020A3FA4A88"},{"vulnerable":true,"criteria":"cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*","versionStartIncluding":"2022.1.0","versionEndExcluding":"2022.1.11","matchCriteriaId":"E4327F71-29F5-42BE-BB63-55912ACD82F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.0.1","versionEndExcluding":"2023.0.8","matchCriteriaId":"8D751E70-646C-4CB4-92A5-A53EB0505025"},{"vulnerable":true,"criteria":"cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*","versionStartIncluding":"2023.1.0","versionEndExcluding":"2023.1.3","matchCriteriaId":"E05648FB-598C-4884-BDFC-6C16C7152016"}]}]}],"references":[{"url":"https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-January-2024","source":"security@progress.com","tags":["Vendor Advisory"]},{"url":"https://www.progress.com/moveit","source":"security@progress.com","tags":["Product"]},{"url":"https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-January-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.progress.com/moveit","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}