Critical Vulnerability in Fortra GoAnywhere MFT
The security update addresses a critical authentication bypass vulnerability affecting GoAnywhere MFT
Summary
The security update addresses a critical authentication bypass vulnerability affecting GoAnywhere MFT
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Fortra has released a security update for a critical vulnerability found in GoAnywhere MFT.
The vulnerability, known as CVE-2024-0204, is an authentication bypass vulnerability. An attacker could exploit this vulnerability to create an admin user via the administration portal.
Proof-of-concept available for CVE-2024-0204
Proof-of-concept code for vulnerability CVE-2024-0204 has been made publicly available, which increases the likelihood of exploitation.
Remediation advice
Affected organisations are encouraged to review the Fortra advisory FI-2024-001 and apply updates as soon as practicable.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 25 January 2024 9:22 am