Progress在6月底揭露與修補MOVEit兩個重大漏洞
支付動態 · 2024-06-26

MOVEit Gateway與MOVEit Transfer存在身分認證略過的資安問題,Progress本週發布資安公告,說明漏洞成因與解決辦法,導入相關系統的企業與組織應儘快清查所用版本,若處於受影響範圍,請升級至原廠發布的新版本

在2023年上半,Progress公司因旗下檔案傳輸管理系統MOVEit的漏洞CVE-2023-34362,遭到駭客濫用,後續藉此攻擊全球32國、兩千多個組織,而鬧得沸沸揚揚,我們也將此弱點列為2023年頭號資安漏洞,本週他們在自家網站的知識庫公告MOVEit產品線有兩個重大漏洞,分別是:位於檔案傳輸代理伺服器MOVEit Gateway的CVE-2024-5805,以及建置在內網環境的檔案傳輸系統MOVEit Transfer的CVE-2024-5806,都是因為當中搭配的SFTP模組,居然允許略過身分認證的程序,所以產生資安漏洞,而這兩個資安弱點的嚴重程度都被評為「重大」,CVSS分數高達9.1分。

為了要解決這樣的問題,Progress現在發布這兩個產品的更新版本。若企業與組織目前採用MOVEit Gateway的2024.0.0版,需為此升級到2024.0.1版,即可修補CVE-2024-5805;若採用MOVEit Transfer的2023.0.0、 2023.1.0、2024.0.0這三個版本,需各自升級到2023.0.11、2023.1.6、2024.0.2。

以監測漏洞暴露在網際網路的全球威脅態勢著稱的非營利組織Shadowserver基金會,在6月25日Progress發布相關消息的當天,就觀察到有心人士蠢蠢欲動。因為他們發現,當這些資訊公開後沒多久,就出現試圖利用CVE-2024-5806的行為,有人想要趁機在系統的根目錄上傳guestaccess.aspx,進行滲透,而且,根據他們的統計,目前暴露在網際網路的Progress系統,至少有1,800臺,雖然這些環境並非全都具有上述漏洞,但可想而知,若攻擊者想要行動,它們勢必會是最先被鎖定的對象。

 

Very shortly after vulnerability details were published today we started observing Progress MOVEit Transfer CVE-2024-5806 POST /guestaccess.aspx exploit attempts. If you run MOVEit & have not patched yet - please do so now: https://t.co/AenLgqg1wM

NVD: https://t.co/OHQRNFNE9p

— The Shadowserver Foundation (@Shadowserver) June 25, 2024

 

關於CVE-2024-5806漏洞,設立於新加坡的新創資安廠商watchTowr其實在Progress公開之前,就已經收到知情人士的通報,因而提前得知這個當時尚未被揭露的弱點,也率先發布部落格文章解析CVE-2024-5806的問題、概念驗證攻擊手法,以及修正與緩解方式。

 

Progress just un-embargoed a very closely guarded auth bypass in MOVEit Transfer's SFTP mechanism - CVE-2024-5806.

We were lucky enough to receive a tip-off :-) Enjoy our analysis, we had a lot of fun.https://t.co/GLoCIAki9w

— watchTowr (@watchtowrcyber) June 25, 2024

 

Popular articles
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
British gambling levy rates confirmed for each vertical
Regulation
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
Kazakhstan plans to penalise online casino promotions
Regulation
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Home
Game
Cooperation
Find
My