VulnerabilityModified
CVE-2017-6195
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection.
CRITICAL 9.8EPSS 1.99%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.99% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- ipswitch/moveit dmz · ipswitch/moveit transfer 2017
- Source
- cve@mitre.org
References
- http://ft.ipswitch.com/rs/751-HBN-596/images/Ipswitch-Security-Bulletin-FT-Vulnerability.pdfPatch, Vendor Advisory
- https://www.siberas.de/assets/papers/ssa-1705_IPSWITCH_SQLinjection.txtThird Party Advisory
- http://ft.ipswitch.com/rs/751-HBN-596/images/Ipswitch-Security-Bulletin-FT-Vulnerability.pdfPatch, Vendor Advisory
- https://www.siberas.de/assets/papers/ssa-1705_IPSWITCH_SQLinjection.txtThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.