CVE-2023-0669: Fortra GoAnywhere MFT Remote Code Execution Vulnerability
Withdrawn This advisory has been withdrawn because it was incorrectly associated with the metasploit-framework package, which is not affected by this CVE, and the actual vulnerable component does not fit within our supported ecosystems. This link is maintained to preserve external references.
Original Description
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.
Other sources
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
— CISA
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-0669?
CVE-2023-0669 is a vulnerability in Fortra (formerly, HelpSystems) GoAnywhere MFT that allows remote code execution.
How can the Fortra GoAnywhere MFT Remote Code Execution Vulnerability be exploited?
The vulnerability can be exploited by sending a specially crafted object to the License Response Servlet.
What is the impact of CVE-2023-0669?
The vulnerability allows an attacker to execute arbitrary code on the affected system, potentially leading to complete compromise of the system.
How can I mitigate the Fortra GoAnywhere MFT Remote Code Execution Vulnerability?
Apply the latest security patches and updates provided by Fortra to fix the vulnerability.
Where can I find more information about CVE-2023-0669?
You can find more information about CVE-2023-0669 on the official CISA website and the Fortra GoAnywhere MFT product documentation.