Security News > 2024 > January > Fortra warns of new critical GoAnywhere MFT auth bypass, patch now
![Fortra warns of new critical GoAnywhere MFT auth bypass, patch now](/static/build/img/news/fortra-warns-of-new-critical-goanywhere-mft-auth-bypass-patch-now-medium.jpg)
Fortra is warning of a new authentication bypass vulnerability impacting GoAnywhere MFT versions before 7.4.1 that allows an attacker to create a new admin user.
GoAnywhere MFT is used by organizations worldwide to secure transfer files with customers and business partners.
The flaw impacts Fortra GoAnywhere MFT 6.x from 6.0.1 and Fortra GoAnywhere MFT 7.4.0 and earlier and was fixed in GoAnywhere MFT 7.4.1, released on December 7, 2023.
Fortra has not clarified if the vulnerability is actively exploited or not.
In early 2023, it was revealed that the Clop ransomware gang had breached 130 companies and organizations by leveraging a critical remote code execution flaw in GoAnywhere MFT. The flaw is tracked as CVE-2023-0669 and had been exploited as a zero-day vulnerability since January 18, 2023.
Considering the above, organizations using Fortra GoAnywhere MFT should apply the available security updates and recommended mitigations as soon as possible and scrutinize their logs for suspicious activity.
News URL
Related news
- Exploit for critical Progress Telerik auth bypass released, patch now (source)
- Exploit for critical Veeam auth bypass available, patch now (source)
- Exploit for Veeam Recovery Orchestrator auth bypass available, patch now (source)
- ASUS warns of critical remote authentication bypass on 7 routers (source)
- ASUS Patches Critical Authentication Bypass Flaw in Multiple Router Models (source)
- VMware fixes critical vCenter RCE vulnerability, patch now (source)
- Hackers target new MOVEit Transfer critical auth bypass bug (source)
- GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others (source)
- Critical Windows licensing bugs, plus two others under attack, top Patch Tuesday (source)
- Netgear warns users to patch auth bypass, XSS router flaws (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-06 | CVE-2023-0669 | Deserialization of Untrusted Data vulnerability in Fortra Goanywhere Managed File Transfer Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. | 7.2 |