KEVIntel
7.2
CVSS
High

CVE-2023-0669

PUBLISHED

Fortra GoAnywhere MFT License Response Servlet Command Injection

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Fortra
Product
Goanywhere MFT
Published
Feb 06, 2023
EPSS

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.1 7.2 High

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-02-10 00:00:00 UTC · Source

Used in malware

Recorded 2023-02-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 10, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

fortra_goanywhere_rce_cve_2023_0669

metasploit · Created Unknown

Metasploit module for CVE-2023-0669

Avento/CVE-2023-0669

github · Created 2023-04-06 03:40:03 UTC · 8 stars

GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)

yosef0x01/CVE-2023-0669-Analysis

github · Created 2023-02-26 02:33:54 UTC · 7 stars

CVE analysis for CVE-2023-0669

0xf4n9x/CVE-2023-0669

github · Created 2023-02-10 13:02:55 UTC · 101 stars

CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit