CVE-2024-0204
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
- Affected products
- Goanywhere Mft
- Fortra Goanywhere Managed File Transfer
- < 7.4.1, 6.0.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 95.1% (100th percentile)
- Weakness
- CWE-425
- NVD status
- Modified
- Published
- 2024-01-22
- Attack patterns
- CAPEC-1
- Entry point
- j_id_u:creteAdminGrid:username path
- Path
- /goanywhere/images/..;/wizard/InitialAccountSetup.xhtml
Fix
Upgrade to version 7.4.1 or higher. The vulnerability may also be eliminated in non-container deployments by deleting the InitialAccountSetup.xhtml file in the install directory and restarting the services. For container-deployed instances, replace the file with an empty file and restart. For additional information, see https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml  (registration required). https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml
Workaround
Users are encouraged to apply defense-in-depth tactics to limit access to the administrative console. Do not expose the console to the internet and apply web application controls such as a WAF, monitoring, and access controls.
10 known exploits for CVE-2024-0204
Proof-of-concept code and exploit modules indexed by Sploitus