Community Health Systems data breach caused by GoAnywhere MFT hack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-0669 | Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%. Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use. | 7.2 | 100% | KEV ransomware PoC ×3 |
| moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface) |
Full article439 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 15, 2023

Community Health Systems (CHS) disclosed a data breach, attackers exploited the zero-day vulnerability in Fortra’s GoAnywhere MFT platform.
Community Health Systems (CHS) is one of the nation’s leading healthcare providers. CHS operates 79 acute-care hospitals and more than 1,000 other sites of care, including physician practices, urgent care centers, freestanding emergency departments, occupational medicine clinics, imaging centers, cancer centers and ambulatory surgery centers.
Community Health Systems (CHS) was the victim of a cyber attack, threat actors exploited the recently disclosed zero-day vulnerability (CVE-2023-0669) in Fortra’s GoAnywhere MFT secure file transfer platform.
Community Health Systems was recently notified by its third-party provider Fortra, that Fortra had experienced a security incident that exposed Company data. CHS launched an investigation to determine whether any its systems were affected and discovered that up to 1 million patients were impacted.
“Upon receiving notification of the security breach, the Company promptly launched an investigation, including to determine whether any Company information systems were affected, whether there was any impact to ongoing operations, and whether and to what extent PHI or PI had been unlawfully accessed by the attacker.” reads a 8-K form filed with the SEC. “While that investigation is still ongoing, the Company believes that the Fortra breach has not had any impact on any of the Company’s information systems and that there has not been any material interruption of the Company’s business operations, including the delivery of patient care. With regard to the PHI and PI compromised by the Fortra breach, the Company currently estimates that approximately one million individuals may have been affected by this attack.“
The company will offer protection services and notify all impacted individuals whose information was exposed in the data breach.
Last week, the Clop ransomware gang told BleepingComputer that they were able to compromise over 130 organizations in just ten days by exploiting the GoAnywhere MFT, but did not share details regarding their claims.
The crooks also claims to have fully compromised the network organizations, but did not deploy any ransomware.
Multiple experts already released exploits for the CVE-2023-0669 vulnerability, on February 6, 2023, the researcher Florian Hauser of IT security consulting firm Code White released a proof-of-concept (PoC) exploit code.
Researchers at threat intelligence firm Huntress shared findings of their investigation into GoAnywhere MFT exploitation and linked the attacks to the TA505 threat actors.
Last week CISA also added the GoAnywhere MFT flaw to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to address it by March 3, 2023.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Community Health Systems)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/142242/data-breach/community-health-systems-data-breach.html