Vulnerability record · CVE-2023-0669 · published 6 February 2023
CVE-2023-0669: Fortra GoAnywhere MFT pre-auth deserialization command injection
Fortra · Goanywhere Managed File Transfer
Fortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. The flaw was patched in version 7.1.2. Because it is remotely reachable and was exploited as a zero-day, it is a serious risk to internet-facing MFT deployments.
Description
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication remote code execution in an internet-facing file transfer product, listed in CISA KEV with known ransomware use and near-maximum EPSS.
What it is
Fortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. The flaw was patched in version 7.1.2. Because it is remotely reachable and was exploited as a zero-day, it is a serious risk to internet-facing MFT deployments.
Impact
An attacker can execute arbitrary commands on the GoAnywhere MFT server, leading to full compromise of the host and any data it manages. CISA KEV notes known ransomware campaign use, and cl0p is documented as using it.
Attack surface
Reached over the network via the License Response Servlet; the description calls it pre-authentication, though the CVSS vector lists PR:H, so the record is inconsistent on required privileges. No user interaction is indicated.
Exploitation
Actively exploited: it is in CISA KEV with a 2023-03-03 due date and known ransomware use, EPSS 30-day probability is 0.99999, and multiple references are tagged Exploit.
What to do
- Upgrade GoAnywhere MFT to version 7.1.2 or later immediately.
- If patching cannot be done at once, restrict network access to the administrative and License Response interfaces to trusted sources.
- Monitor for and block exploitation attempts against the License Response Servlet.
- Review the vendor advisory and Rapid7 mitigation guidance for interim controls.
- After patching, hunt for signs of prior compromise given known ransomware use.
Detection
- Inspect web/proxy logs for requests to the GoAnywhere License Response Servlet, especially unusual or malformed payloads.
- Monitor for unexpected child processes spawned by the GoAnywhere MFT service or Java process.
- Look for outbound connections or file writes from the GoAnywhere host that do not match normal MFT behavior.
- Correlate with CISA KEV and known cl0p ransomware indicators for post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-0669 to the Known Exploited Vulnerabilities catalog on 10 February 2023 as "Fortra GoAnywhere MFT Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 March 2023.
Ransomware crews whose documented playbooks reference this CVE: