peter bassill · operator
$ cve CVE-2024-0204 JSON

CVE-2024-0204 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 95.1% (pctl 100)

Patch early

A public exploit exists.

Description

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS95.09% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-425
On CISA KEVno
Public exploityes
Published2024-01-22
Last modified2026-06-17

Affected (1)

VendorProduct
fortragoanywhere managed file transfer

Public exploits

SourceTitleDate
exploit-dbFortra GoAnywhere MFT 7.4.1 - Authentication Bypass2025-05-29

References

→ the Explorer  ·  watch your stack  ·  NVD