CVE-2025-1241: Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1241?
CVE-2025-1241 is considered a high severity vulnerability due to its potential for brute-force decryption of sensitive data.
How do I fix CVE-2025-1241?
To fix CVE-2025-1241, upgrade to Fortra GoAnywhere MFT version 7.10.0 or higher and GoAnywhere Agents version 2.2.0 or higher.
What types of data are affected by CVE-2025-1241?
CVE-2025-1241 affects encrypted values stored in Fortra's GoAnywhere MFT and GoAnywhere Agents prior to the specified versions.
Who is impacted by CVE-2025-1241?
Admin users of Fortra GoAnywhere MFT and GoAnywhere Agents who operate on versions before 7.10.0 and 2.2.0 respectively are impacted by CVE-2025-1241.
What is the cause of CVE-2025-1241?
CVE-2025-1241 is caused by the use of a static Initialization Vector (IV) in the encryption process, enabling brute-force decryption.