Fortra GoAnywhere MFT
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*
- < 7.10.0
A vulnerability exists in Fortra's GoAnywhere MFT SFTP service in versions prior to 7.10.0. The issue arises because the login limit is not enforced for Web Users configured to authenticate using SSH keys. This lack of restriction allows for brute force attacks to guess the SSH keys.
Exploitation of this vulnerability could lead to successful brute force attacks on SSH key authentication, potentially allowing unauthorized access.
Users are advised to upgrade to GoAnywhere MFT version 7.10.0 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.