CVE detail
CVE-2019-18465 — CVE-2019-18465
Published 2019-10-31 · Modified 2026-06-17 · Vendor ipswitch · Product moveit_transfer · Source nvd
CRITICAL
severity
CVSS-derived band
0.0149
EPSS probability
exploitation probability, 30d
72.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References