RULE(RULE ID:337804)

Rule General Information
Release Date: 2024-01-29
Rule Name: GoAnywhere MFT Authentication Bypass Vulnerability (CVE-2024-0204)
Severity:
CVE ID:
Rule Protection Details
Description: Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference: https://www.fortra.com/security/advisory/fi-2024-001
https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml
https://cxsecurity.com/cveshow/CVE-2024-0204/
Solutions
Refer to the announcement or patch by the vendor: https://www.fortra.com/security/advisory/fi-2024-001