CVE-2024-0204

Authentication Bypass in GoAnywhere MFT

Basic Information

CVE State
PUBLISHED
Reserved Date
January 03, 2024
Published Date
January 22, 2024
Last Updated
May 30, 2025
Vendor
Fortra
Product
GoAnywhere MFT
Description
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Tags
nuclei_scanner metasploit_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

Score
93.32% (Percentile: 99.80%) as of 2025-05-22

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-05-05 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-24 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

fortra_goanywhere_mft_rce_cve_2024_0204

Type: metasploit • Created: Unknown

Metasploit module for CVE-2024-0204

m-cetin/CVE-2024-0204

Type: github • Created: 2024-01-24 20:10:34 UTC • Stars: 2

This script exploits the CVE-2024-0204 vulnerability in Fortra GoAnywhere MFT, allowing the creation of unauthorized administrative users, for educational and authorized testing purposes.

cbeek-r7/CVE-2024-0204

Type: github • Created: 2024-01-23 22:42:58 UTC • Stars: 4

Scanning for vulnerable GoAnywhere MFT CVE-2024-0204

horizon3ai/CVE-2024-0204

Type: github • Created: 2024-01-23 20:16:14 UTC • Stars: 61

Authentication Bypass in GoAnywhere MFT

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit