S4E just found a high [ai] pa ssl inspection control
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-0669 Scanner

CVE-2023-0669 scanner - Remote Code Execution (RCE) vulnerability in Fortra GoAnywhere MFT

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-0669
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Goanywhere MFTby Fortra
0
Updated Aug 19, 2026View on NVD →
Detail

Fortra (formerly, HelpSystems) GoAnywhere MFT is a managed file transfer solution designed for businesses that need secure file transfer and file sharing capabilities. It provides a centralized control panel for file transfers, encryption, compression, and monitoring, making it a comprehensive solution for enterprises that handle sensitive data. It is used across various industries, such as finance, healthcare, retail, and manufacturing.

However, a pre-authentication command injection vulnerability in the License Response Servlet was discovered in the Fortra GoAnywhere MFT, assigned CVE-2023-0669. The vulnerability is caused by the deserialization of an arbitrary attacker-controlled object. This action can be exploited by an attacker to execute arbitrary code remotely without proper authentication measures. Successful exploitation of this vulnerability could provide unauthorized access to management and encryption keys, leading to the compromise of sensitive data. The vulnerability poses a significant threat to businesses relying on the Fortra GoAnywhere MFT solution.

When exploited, CVE-2023-0669 allows an attacker to execute code remotely, leading to tampering with the intended behavior of the software, the ability to read and modify data contained within the system, total system compromise or control, and the escalation of privileges. The intrusion can ultimately result in the theft or destruction of sensitive data, loss of business reputation, and revenue loss.

In conclusion, businesses that rely on the Fortra GoAnywhere MFT solution must take immediate measures to protect themselves against CVE-2023-0669. At s4e.io, we pride ourselves on providing cutting-edge cybersecurity solutions. Thanks to our pro features, readers can quickly and easily learn about vulnerabilities in their digital assets and stay up-to-date on the latest trends in the cybersecurity industry. Trust us to keep your digital enterprise secure, so you can focus on growth and success.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses relying on the Fortra GoAnywhere MFT solution must take the following precautions:

  • Install the latest version of Fortra GoAnywhere MFT, version 7.1.2, which has a patch for the vulnerability
  • Implement strong authentication measures to restrict access to the License Response Servlet
  • Add a Web Application Firewall (WAF) to the infrastructure
  • Use a secure development lifecycle for all production and non-production systems
  • Run regular vulnerability assessments, penetration testing, and code reviews

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.