CVE-2025-10932

8.2

Progress · MOVEit Transfer

Progress MOVEit Transfer contains an uncontrolled resource consumption vulnerability in the AS2 module that allows unauthenticated attackers to trigger a denial of service.

Executive summary

An unauthenticated remote denial of service vulnerability in the Progress MOVEit Transfer AS2 module poses a significant risk to system availability.

Vulnerability

The AS2 module within MOVEit Transfer is susceptible to uncontrolled resource consumption, identified as CWE-400. This flaw allows an unauthenticated attacker to remotely exhaust system resources, leading to a service disruption.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can render critical file transfer operations unavailable. Given the CVSS score of 8.2, this vulnerability is classified as High severity because the attack vector is network-based and requires no authentication, making it highly automatable for malicious actors.

Remediation

Immediate Action: Upgrade to MOVEit Transfer version 2025.0.3, 2024.1.7, 2023.1.16, or later, as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for unusual spikes in resource utilization or repeated connection attempts directed at the AS2 module.

Compensating Controls: Deploy Web Application Firewall rules to rate-limit traffic to the AS2 endpoint and restrict access to authorized IP addresses where feasible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing MOVEit Transfer should prioritize applying the provided patches to mitigate the risk of service disruption. Given the high CVSS score and the ease of exploitation, immediate patching is strongly recommended to maintain operational continuity and system stability.

More Progress CVEs

Sources