Home
MEDIUM: 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version before 7.9.0
affected
Description
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
CWE-863 Incorrect Authorization
Product status
Any version before 7.9.0
References
www.fortra.com/...ty/advisories/product-security/fi-2025-013