CVE-2023-0669
Fortra GoAnywhere MFT Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.2
- EPSS
- 100.0% 백분위 100.0% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.03.03
- 공개일
- 2023.02.07
CISA KEV에 등록된 실제 악용 확인 취약점
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
공급사 Fortra
제품 GoAnywhere MFT
영향 버전 0, < 7.1.2
수정 버전 7.1.2
Apply updates per vendor instructions.
조치 기한: 2023.03.03CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE CWE-502
KEV 등록일 2023.02.10
랜섬웨어 캠페인 사용 확인됨
CISA 비고 This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch.; https://nvd.nist.gov/vuln/detail/CVE-2023-0669
EPSS 데이터 기준일 2026.06.27