CVE-2025-10932
8.2Progress · MOVEit Transfer
Progress MOVEit Transfer contains an uncontrolled resource consumption vulnerability in the AS2 module that allows unauthenticated attackers to trigger a denial of service.
Executive summary
An unauthenticated remote denial of service vulnerability in the Progress MOVEit Transfer AS2 module poses a significant risk to system availability.
Vulnerability
The AS2 module within MOVEit Transfer is susceptible to uncontrolled resource consumption, identified as CWE-400. This flaw allows an unauthenticated attacker to remotely exhaust system resources, leading to a service disruption.
Business impact
Successful exploitation of this vulnerability results in a denial of service, which can render critical file transfer operations unavailable. Given the CVSS score of 8.2, this vulnerability is classified as High severity because the attack vector is network-based and requires no authentication, making it highly automatable for malicious actors.
Remediation
Immediate Action: Upgrade to MOVEit Transfer version 2025.0.3, 2024.1.7, 2023.1.16, or later, as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unusual spikes in resource utilization or repeated connection attempts directed at the AS2 module.
Compensating Controls: Deploy Web Application Firewall rules to rate-limit traffic to the AS2 endpoint and restrict access to authorized IP addresses where feasible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing MOVEit Transfer should prioritize applying the provided patches to mitigate the risk of service disruption. Given the high CVSS score and the ease of exploitation, immediate patching is strongly recommended to maintain operational continuity and system stability.