Progress MOVEit Transfer
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*
- < 2024.1.8
- >= 2025.0.0, < 2025.0.4
A Server-Side Request Forgery (SSRF) vulnerability exists in Progress MOVEit Transfer versions prior to 2024.1.8 and in the 2025.0.0 to 2025.0.4 range. This vulnerability could lead to unnecessary DNS requests originating from the MOVEit server.
Exploitation of this vulnerability could cause the MOVEit Transfer server to make unnecessary DNS requests, potentially leading to DNS amplification or other related issues.
Users can upgrade to MOVEit Transfer version 2024.1.8 or 2025.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.