Missing Authorization in GoAnywhere MFT - CVE-2024-0204
Published: January 24, 2024 / Updated: May 30, 2025
Vulnerability identifier: #VU85739
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0204
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
Exploit example to access the initial setup page bypassing the authorization check:
https://[host]:8001/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml
Affected software
GoAnywhere MFT
Chrome OS
Chrome OS
How to mitigate CVE-2024-0204
Install updates from vendor's website.
GoAnywhere MFT - update to 7.4.1
Chrome OS - update to 120.0.6099.301
Chrome OS - update to 120.0.6099.301
Links to Public Exploits and PoC-codes
- Exploit #11424 - CVE-2024-0204 (CVE-2024-0204 was discovered in January 2024 and affects all GoAnywhere MFT versions prior to 7.4.1. This vulnerability has been rated as Critical (CVSS 9.8) due to its ease of exploitation and the complete administrative access it provides (May 30, 2025)
- Exploit #9539 - Fortra GoAnywhere MFT Unauthenticated Remote Code Execution (February 2, 2024)
- Exploit #9526 - CVE-2024-0204 (January 26, 2024)
- Exploit #9522 - CVE-2024-0204 (January 24, 2024)