SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-0669

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

KEVHIGH 7.2EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 March 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 10 February 2023 · due 3 March 2023 · used in ransomware campaigns
Weakness
CWE-502
Affected
fortra/goanywhere managed file transfer
Source
cve@rapid7.com

CISA notes

Apply updates per vendor instructions. This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch.; https://nvd.nist.gov/vuln/detail/CVE-2023-0669

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.