CVE-2023-0669
גבוהה 7.2 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Fortra GoAnywhere MFT Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
fortra: goanywhere managed file transfer
קישורים
- https://github.com/rapid7/metasploit-framework/pull/17607 Patch
- https://github.com/rapid7/metasploit-framework/pull/17607 Patch
- http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1… ExploitThird Party AdvisoryVDB Entry
- https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis ExploitThird Party Advisory
- https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html ExploitThird Party Advisory
- http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1… ExploitThird Party AdvisoryVDB Entry
- https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis ExploitThird Party Advisory
- https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html ExploitThird Party Advisory
- https://duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywh… Broken LinkThird Party Advisory
- https://infosec.exchange/@briankrebs/109795710941843934 MitigationThird Party Advisory