Fortra GoAnywhere MFT
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*
- < 2.2.0
A vulnerability exists in Fortra's GoAnywhere MFT versions prior to 7.10.0 and GoAnywhere Agents versions prior to 2.2.0, where encrypted values use a static initialization vector (IV). This flaw enables admin users to brute-force the decryption of data.
Exploitation of this vulnerability could lead to unauthorized decryption of sensitive data, potentially allowing for data exposure or misuse.
Users are advised to update to Fortra GoAnywhere MFT version 7.10.0 or later, and GoAnywhere Agents version 2.2.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.