Impact
The vulnerability is an incorrect authorization flaw in the AuditUser module of Progress MOVEit Transfer that allows users granted the AuditUser role to information and therefore breaches confidentiality. The weakness is a missing authentication/authorization defect (CWE‑863).
Affected Systems
The affected vendor is Progress, product MOVEit Transfer. Versions before 2025.0.7 and from 2025.1.0 up to but not including 2025.1.3 are vulnerable.
Risk and Exploitability
The CVSS score of 2.7 indicates low overall severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated session with a user possessing the AuditUser role, so the threat is internal or arises from compromised credentials rather than remote exploitation.
OpenCVE Enrichment