PatchSiren cyber security CVE debrief
CVE-2023-34362 Progress CVE debrief
CVE-2023-34362 is a SQL injection vulnerability in Progress MOVEit Transfer. CISA added it to the Known Exploited Vulnerabilities catalog on the same date it was published and marked it as known exploited, with known ransomware campaign use.
- Vendor
- Progress
- Product
- MOVEit Transfer
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2023-06-02
- Original CVE updated
- 2023-06-02
- Advisory published
- 2023-06-02
- Advisory updated
- 2023-06-02
Who should care
Organizations running Progress MOVEit Transfer, especially security teams, vulnerability management teams, and incident responders responsible for externally exposed file transfer systems.
Technical summary
The supplied records identify CVE-2023-34362 as a SQL injection issue in Progress MOVEit Transfer. CISA’s KEV entry classifies it as known exploited, with a remediation due date of 2023-06-23 and a note pointing to CISA AA23-158A for associated indicators of compromise.
Defensive priority
Urgent. This is a CISA-known exploited vulnerability with a short remediation window and documented ransomware-campaign association in the supplied metadata.
Recommended defensive actions
- Apply updates per vendor instructions.
- Review CISA AA23-158A for associated IOCs and use them to assess your environment.
- Prioritize any internet-facing Progress MOVEit Transfer deployments for immediate remediation and verification.
- Confirm whether the affected product is present in your environment and track remediation to completion before the KEV due date.
Evidence notes
Based only on the supplied CISA KEV feed item, the CVE record metadata, and official reference links. The source metadata states vendor Project Progress, product MOVEit Transfer, vulnerability type SQL injection, known exploitation, known ransomware campaign use, date added 2023-06-02, due date 2023-06-23, and a pointer to CISA AA23-158A for IOCs.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-34362 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-34362
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-34362 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-34362
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.