ZeroHour

CVE-2023-0669

KEV ransomware PoC ×3moderate1

Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

CISA: Fortra GoAnywhere MFT Remote Code Execution Vulnerability

CVSS 3.1
7.2 high
EPSS
100%p100
Published
()
KEV added
AI analysis

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

What to do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

Affected
Fortra GoAnywhere MFT
Estimated exposure
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface) — GoAnywhere MFT is enterprise managed-file-transfer software deployed mainly by a few thousand organizations, and public internet scans typically find on the order of thousands of reachable instances, so plausibly affected exposed systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

CISA Known Exploited Vulnerability
Affected
Fortra GoAnywhere MFT
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
fortra
Products
goanywhere managed file transfer
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news