{"id":"CVE-2023-0669","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-0669","summary":"Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled…","details":"Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.","published":"2023-02-06T20:15:14.300","modified":"2026-08-06T05:16:38.057","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99999,"percentile":0.99996,"asOf":"2026-09-05"},"cisaKev":null,"exploitsKnown":13,"affectedPackages":[],"fix":{"url":"https://github.com/rapid7/metasploit-framework/pull/17607","label":"rapid7/metasploit-framework#17607"},"references":[{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis"},{"type":"ADVISORY","url":"https://duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mft"},{"type":"EXPLOIT","url":"https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html"},{"type":"FIX","url":"https://github.com/rapid7/metasploit-framework/pull/17607"},{"type":"ADVISORY","url":"https://infosec.exchange/@briankrebs/109795710941843934"},{"type":"WEB","url":"https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1"},{"type":"ADVISORY","url":"https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis"},{"type":"ADVISORY","url":"https://duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mft"},{"type":"EXPLOIT","url":"https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html"},{"type":"FIX","url":"https://github.com/rapid7/metasploit-framework/pull/17607"},{"type":"ADVISORY","url":"https://infosec.exchange/@briankrebs/109795710941843934"},{"type":"WEB","url":"https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1"},{"type":"ADVISORY","url":"https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-0669"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-06T05:16:38.057"}}