CVE-2017-6195: Ipswitch MOVEit Dmz

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.

Affected products

  • Ipswitch MOVEit Dmz: up to and including 8.1; version 8.2 only; version 8.3 only
  • Ipswitch MOVEit Transfer 2017: version 9.0 only

Published 2017-05-18. Last modified 2026-06-17.