We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3871

Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier



Description

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP.

Reserved 2025-04-22 | Published 2025-07-16 | Updated 2025-07-16 | Assigner Fortra


MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version before 7.8.1
affected

References

www.fortra.com/...ty/advisories/product-security/FI-2025-009

cve.org (CVE-2025-3871)

nvd.nist.gov (CVE-2025-3871)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3871

Support options

Helpdesk Chat, Email, Knowledgebase