CVE-2023-0669: Fortra GoAnywhere MFT Remote Code Execution Vulnerability.
Fortra GoAnywhere MFT Remote Code Execution Vulnerability. Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
- CISA KEV-listed (remediation due 2023-03-03)
- used in ransomware campaigns
- EPSS 100.0% (100.0% percentile)
- CVSS 7.2 high