Skip to content
COOEY

EXPOSURES › CVE-2023-34362

CVE-2023-34362

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-34362 ↗
◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatcheddata-breach

An unauthenticated SQL injection flaw in Progress MOVEit Transfer allowed attackers to alter or delete database elements, leading to a ransomware-linked breach.

Progress MOVEit Transfer contained a SQL injection vulnerability enabling unauthenticated attackers to execute arbitrary SQL commands, altering or deleting database elements. This critical flaw was actively exploited in the wild and linked to ransomware attacks, causing mass data breaches. DIB organizations must ensure MOVEit is patched and monitored, as unpatched CVEs are a primary vector for ransomware and data exfiltration.

Shame score — A critical, unpatched SQL injection flaw was actively exploited in the wild to cause ransomware-linked data breaches, demonstrating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.