{"id":"CVE-2024-0204","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-0204","summary":"Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.","details":"Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.","published":"2024-01-22T18:05:13.194Z","modified":"2025-05-30T14:22:31.288Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.95086,"percentile":0.99855,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":7,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.fortra.com/security/advisory/fi-2024-001"},{"type":"WEB","url":"https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml"},{"type":"WEB","url":"http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/176974/Fortra-GoAnywhere-MFT-Unauthenticated-Remote-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2025-05-30T14:22:31.288Z"}}