Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-0669

98
FAUCET Score

CVE-2023-0669 is a critical pre-authentication command injection vulnerability in Fortra GoAnywhere MFT's License Response Servlet, stemming from unsafe deserialization of attacker-controlled objects. With a CVSS score of 7.2 (HIGH), it allows unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with high impact. This vulnerability is actively exploited in the wild, including in ransomware campaigns, and has publicly available exploit modules and templates. It has garnered significant community attention and media coverage, underscoring its severe risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.1.2CPE matchmatch criteria
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
100.00%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Feb 10, 2023
Metasploit: Fortra GoAnywhere MFT Unsafe Deserialization RCE · Feb 1, 2023
Nuclei: CVE-2023-0669 · Feb 10, 2023
ExploitDB: EDB-51339 · Apr 8, 2023
This CVE's current EPSS score of 1.0000 is in the 100th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

rubygemsGHSA-6pm2-j2v8-h3cjhigh

Withdrawn: Fortra GoAnywhere MFT Deserialization of Untrusted Data vulnerability affects metasploit-framework

Feb 6, 2023

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html
ExploitThird Party AdvisoryVDB Entry
attackerkb.com / topics/mg883Nbeva/cve-2023-0669/rapid7-analysis
ExploitThird Party Advisory
duo.com / decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mft
Broken LinkThird Party Advisory
frycos.github.io / vulns4free/2023/02/06/goanywhere-forgotten.html
ExploitThird Party Advisory
github.com / rapid7/metasploit-framework/pull/17607
Patch
infosec.exchange / @briankrebs/109795710941843934
MitigationThird Party Advisory
my.goanywhere.com / webclient/ViewSecurityAdvisories.xhtml
Product
rapid7.com / blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability
MitigationThird Party Advisory