Vulnerability Intelligence Report
Authentication Bypass in GoAnywhere MFT
CVE-2024-0204
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Nuclei Template
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:95.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-425 ↗CWE-425 Direct Request ('Forced Browsing')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortra | GoAnywhere MFT | 6.0.1 < 7.4.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Fortra, LLC · Vendor · USA |
| Reserved | 2024-01-03T00:12:28 |
| Published | 2024-01-22T18:05:13 |
| Last Updated | 2025-05-30T14:22:31 |
Community Chatter & Buzz