Skip to main content

Critical Vulnerability in Fortra GoAnywhere MFT

The security update addresses a critical authentication bypass vulnerability affecting GoAnywhere MFT

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The security update addresses a critical authentication bypass vulnerability affecting GoAnywhere MFT


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Fortra has released a security update for a critical vulnerability found in GoAnywhere MFT.

The vulnerability, known as CVE-2024-0204, is an authentication bypass vulnerability. An attacker could exploit this vulnerability to create an admin user via the administration portal.

Proof-of-concept available for CVE-2024-0204

Proof-of-concept code for vulnerability CVE-2024-0204 has been made publicly available, which increases the likelihood of exploitation.


Remediation advice

Affected organisations are encouraged to review the Fortra advisory FI-2024-001 and apply updates as soon as practicable. 


Definitive source of threat updates


Last edited: 25 January 2024 9:22 am