CVE-2024-0396 - Missing Server-Side Input Validation leads to computational errors and potential denial of service in Progress MOVEit Transfer
1. Vulnerability Properties
Title: Missing Server-Side Input Validation leads to computational errors and potential denial of service in Progress MOVEit Transfer CVE ID: CVE-2024-0396 CVSSv3 Base Score: 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H) Vendor: Progress Software Corporation (Progress) Products: Progress MOVEit Transfer Advisory Release Date: 18-01-2024 Advisory URL: https://labs.integrity.pt/advisories/cve-2024-0396 Credits: Discovery by Pedro Valadares Pinho <pedro.pinho[at]devoteam.com>
2. Vulnerability Summary
In Progress MOVEit Transfer an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.