CVE-2024-0204
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
9.8
CVSS
95.1%
EPSS (exploit prob.)
100th
EPSS percentile
2024-01-22
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-425
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortra | goanywhere_managed_file_transfer | >= 7.0.0, < 7.4.1 |
| fortra | goanywhere_managed_file_transfer | 6.0.0 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html
- http://packetstormsecurity.com/files/176974/Fortra-GoAnywhere-MFT-Unauthenticated-Remote-Code-Execution.html
- https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml
- https://www.fortra.com/security/advisory/fi-2024-001
- http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html
- http://packetstormsecurity.com/files/176974/Fortra-GoAnywhere-MFT-Unauthenticated-Remote-Code-Execution.html
- https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml
- https://www.fortra.com/security/advisory/fi-2024-001
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-0204