QID 731096

Date Published: 2024-01-23

QID 731096: GoAnywhere Managed File Transfer (MFT) Authentication Bypass Vulnerability

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Affected Versions:
All versions of GoAnywhere MFT prior to version 7.4.1

QID Detection Logic (Unauhtenticated):
This QID checks for vulnerable GoAnywhere MFT target by sending a GET request to the '/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml' endpoint and checks if the Account Setup page is accessible.

Successful exploitation of the vulnerability may allow a remote unauthenticated user create an admin user via the administration portal, leading to complete system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to GoAnywhere Managed File Transfer (MFT) 7.4.1 or later. For more information, please refer to FI-2024-001

    Vendor References

    CVEs related to QID 731096

    Software Advisories
    Advisory ID Software Component Link
    fi-2024-001 URL Logo www.fortra.com/security/advisory/fi-2024-001