CVE-2024-0204 is a critical authentication bypass vulnerability affecting Fortra's GoAnywhere MFT prior to version 7.4.1, allowing an unauthorized user to create an administrative account. With a CVSS score of 9.8 (CRITICAL), this flaw requires no authentication or user interaction, making it easily exploitable with full confidentiality, integrity, and availability impact. Exploit code, including Metasploit modules and Nuclei templates, is publicly available and widely discussed within the cybersecurity community, as evidenced by numerous mentions and media coverage. While not yet officially listed in the KEV catalog, its high EPSS score and FAUCET Risk Score of 100/100 indicate a very high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.4.1CPE matchmatch criteria | cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:fortra:goanywhere_managed_file_transfer:6.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.