HIGH

CVE-2023-0669

Fortra Goanywhere Managed File Transfer 2023-02-06 CVSS v3.1
CVSS
7.2
KEV

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

Summary dbcve.org

Fortra GoAnywhere MFT contains a pre-authentication deserialization vulnerability in the License Response Servlet that allows remote attackers to inject commands by submitting a malicious serialized Java object. This enables unauthenticated remote code execution without requiring valid credentials.

Mitigation

Upgrade GoAnywhere MFT to version 7.1.2 or later to apply the patch. If immediate patching is not feasible, restrict network access to the License Response Servlet via firewall or network segmentation to reduce attack surface.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE