CVE-2023-0669

high

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

References

https://www.itsecurityguru.org/2025/10/13/hidden-cost-of-mft-vulnerabilities-why-cve-2025-10035-demands-a-new-security-playbook/?utm_source=rss&utm_medium=rss&utm_campaign=hidden-cost-of-mft-vulnerabilities-why-cve-2025-10035-demands-a-new-security-playbook

https://www.darkreading.com/vulnerabilities-threats/medusa-ransomware-exploit-fortra-goanywhere-flaw

https://therecord.media/cisa-orders-federal-gov-patch-fortra-bug

https://www.theregister.com/2025/09/26/an_apts_playground_goanywhere_perfect10/

https://cyberscoop.com/goanywhere-vulnerability-active-exploitation-september-2025/

https://hackread.com/critical-cvss-10-flaw-goanywhere-file-transfer/

https://www.securityweek.com/fortra-patches-critical-goanywhere-mft-vulnerability/

https://www.helpnetsecurity.com/2025/09/22/fortra-goanywhere-vulnerability-cve-2025-10035/

https://www.theregister.com/2025/09/19/gortra_goanywhere_bug/

https://www.bleepingcomputer.com/news/security/fortra-warns-of-max-severity-flaw-in-goanywhere-mfts-license-servlet/

https://thehackernews.com/2025/09/fortra-releases-critical-patch-for-cvss.html

https://cyberscoop.com/goanywhere-file-transfer-service-vulnerability-september-2025/

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a

https://blog.talosintelligence.com/common-ransomware-actor-ttps-playbooks/

https://www.bleepingcomputer.com/news/security/exploit-for-critical-fortra-filecatalyst-workflow-sqli-flaw-released/

https://research.checkpoint.com/2024/sharp-dragon-expands-towards-africa-and-the-caribbean/

https://services.google.com/fh/files/misc/m-trends-2024.pdf

https://github.com/rapid7/metasploit-framework/pull/17607

Details

Source: Mitre, NVD

Published: 2023-02-06

Updated: 2025-07-30

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.94403