GoAnywhere MFT

Fortra GoAnywhere MFT was exploited through an authentication bypass that exposed the administrative console, chained with an insecure-deserialization flaw in that console that executed attacker-controlled objects, yielding remote code execution on the appliance. The admin-console exposure stemmed from a licensing or servlet endpoint reachable without authentication.

text
GoAnywhere chain:
- Authentication bypass exposing the admin console endpoint
- Insecure deserialization in the admin interface -> remote code execution
- Appliance compromise and bulk data access

Exploitation notes#

  • The bypass hinges on reaching an admin servlet or endpoint that should be internal; the fix guidance was to restrict that path.
  • Deserialization gives clean RCE once the admin surface is reachable, the same pattern as other MFT compromises.
  • Both internet-facing and internally-exposed admin consoles are in scope, so segmentation matters to reachability.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more