vulnerability

Fortra GoAnywhere MFT: CVE-2024-25157: Incorrect Implementation of Authentication Algorithm

Severity
8
CVSS
(AV:N/AC:L/Au:M/C:C/I:C/A:N)
Published
Aug 14, 2024
Added
Aug 19, 2025
Modified
Aug 19, 2025

Description

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

Solution

fortra-goanywhere-mft-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.