PT-2023-1431 · Fortra · Fortra Goanywhere Mft

Brian Krebs

+4

·

Published

2023-02-01

·

Updated

2026-03-08

·

CVE-2023-0669

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortra GoAnywhere MFT versions prior to 7.1.2
Description Fortra GoAnywhere MFT is susceptible to a pre-authentication command injection due to the deserialization of attacker-controlled objects within the License Response Servlet. The Clop ransomware group actively exploited this issue, identified as CVE-2023-0669, to steal data from over 130 organizations within a ten-day period. The vulnerability allows attackers to execute arbitrary code by sending a POST request to the /goanywhere/lic/accept endpoint with a malicious object. The exploitation of this vulnerability has been linked to TA505 and the Clop ransomware group, mirroring tactics used in previous attacks against Accellion FTA in 2021. The vulnerability requires the administrative functions to be exposed over the internet, typically on ports 8000/tcp and 8001/tcp/tls.
Recommendations Update Fortra GoAnywhere MFT to version 7.1.2 or later. Restrict access to the administrative console to prevent external access. As a temporary workaround, consider disabling the License Response Servlet until a patch can be applied. Monitor network traffic and logs for suspicious activity related to the /goanywhere/lic/accept endpoint.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00833
CVE-2023-0669
GHSA-6PM2-J2V8-H3CJ

Affected Products

Fortra Goanywhere Mft