← volver
CVE-2025-8148

CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT

CVSS 4.2 MEDIUMEPSS 0.1%CWE-732CWE-863
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Productos afectados
Fortra · GoAnywhere MFT

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →