Impact
Based on the description, the vulnerability is a relative path traversal flaw in the Admin Settings module of Progress MOVEit Transfer that allows users with administrative privileges to request and read arbitrary files on the host system. This flaw permits viewing of any file readable by the MOVEit service, potentially exposing confidential data. The weakness is identified as CWE-23, indicating its use for unauthorized information disclosure.
Affected Systems
The affected products are Progress MOVEit Transfer. Versions prior to 2025.0.7 and versions from 2025.1.0 up to, but not including, 2025.1.3 are vulnerable. All other released versions are presumed unaffected.
Risk and Exploitability
Based on the available data, the likely attack vector is an authenticated request to the MOVEit admin interface, requiring administrative privileges. The CVSS score of 4.5 places the issue in a Medium severity level, and an EPSS score of < 1% indicates an extremely low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation results in confidentiality compromise of system files, with no immediate denial of service or code execution.
OpenCVE Enrichment