Fortra Security Update – 24 January 2024

Fortra has released a security update to address a critical vulnerability in multiple versions of Fortra GoAnywhere MFT (Managed File Transfer).

The addressed vulnerability could allow the unauthorized remote attacker to create admin users via the administration portal which could lead to a complete device takeover, access sensitive data, introduce malware, and potentially enable further attacks within the network.

GoAnywhere MFT Authentication Bypass Vulnerability (CVE-2024-0204):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

Affected products:

  • Fortra GoAnywhere MFT 6.x From 6.0.1.
  • Fortra GoAnywhere MFT 7.x Before 7.4.1.
Vulnerabilities

CVE-2024-0204

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Fortra Security Advisory

References