← Back to CVE List
Vulnerability Intelligence Report
Authentication Bypass in GoAnywhere MFT

CVE-2024-0204

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Nuclei Template
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:95.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-425 ↗CWE-425 Direct Request ('Forced Browsing')

Affected Products & Versions

Vendor Product Affected Versions
Fortra GoAnywhere MFT 6.0.1 < 7.4.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
95.086%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityFortra, LLC · Vendor · USA
Reserved2024-01-03T00:12:28
Published2024-01-22T18:05:13
Last Updated2025-05-30T14:22:31

LINK COPIED TO CLIPBOARD