QID 150801

Date Published: 2024-02-14

QID 150801: Fortra GoAnywhere MFT Authentication Bypass Vulnerability (CVE-2024-0204)

Fortra GoAnywhere Managed File Transfer (MFT) is a secure file transfer solution that organizations use to exchange their data safely.

An Authentication bypass vulnerability exists in Fortra's GoAnywhere MFT which allows an unauthorized user to create an admin user via the administration portal.

Affected Versions:
GoAnywhere MFT prior to version 7.4.1

QID Detection Logic (Unauthenticated):
This QID sends an HTTP GET request to the "/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml" endpoint and checks accessibility to the Administrator Account Setup Page.

Successful exploitation of this vulnerability could allow an remote unauthorized user to create an admin user via the administration portal.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade GoAnywhere Managed File Transfer (MFT) to version 7.4.1 or later to remediate this vulnerability. For more information, please refer Fortra Security Advisory.
    Vendor References

    CVEs related to QID 150801

    Software Advisories
    Advisory ID Software Component Link
    Fortra Security Advisory URL Logo www.fortra.com/security/advisory/fi-2024-001