Impact
This flaw allows an attacker to spoof the IPv6 loopback Host header in HTTP requests sent to the MOVEit Transfer HTTPS module, thereby bypassing the origin that normally authenticates the source. The result is a limited authentication bypass, enabling the attacker to act as a legitimate user for the duration of the session without possessing valid credentials. This vulnerability is classified as CWE‑290, improper enforcement of authentication, and does not provide remote code execution or direct data loss beyond the compromised authentication.
Affected Systems
Progress MOVEit Transfer versions before 2025.0.7 and the 2025.1.0 through 2025.1.2 releases are affected. Any deployments running these releases lack the fixes incorporated in 2025.0.7 and 2025.1.3.
Risk and Exploitability
The CVSS score of 3.7 places the issue in the low severity range. The EPSS score of < 1% indicates a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation pressure. The likely attack vector is remote: an adversary can send crafted HTTP requests with a spoofed IPv6 loopback Host header to the exposed HTTPS endpoint of MOVEit Transfer to achieve the bypass. Because the flaw centers on authentication bypass rather than privilege escalation or system compromise, the overall risk to confidentiality, integrity, or availability is constrained to the affected session and any resources the user can access through that session.
OpenCVE Enrichment