{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-0669",
        "assignerOrgId": "9974b330-7714-4307-a722-5648477acda7",
        "state": "PUBLISHED",
        "assignerShortName": "rapid7",
        "dateReserved": "2023-02-03T22:09:23.898Z",
        "datePublished": "2023-02-06T19:16:19.265Z",
        "dateUpdated": "2026-08-06T03:55:37.886Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Goanywhere MFT",
                    "vendor": "Fortra",
                    "versions": [
                        {
                            "lessThanOrEqual": "7.1.1",
                            "status": "affected",
                            "version": "0",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "other",
                    "user": "00000000-0000-4000-9000-000000000000",
                    "value": "Brian Krebs of Krebs on Security"
                },
                {
                    "lang": "en",
                    "type": "analyst",
                    "user": "00000000-0000-4000-9000-000000000000",
                    "value": "Ron Bowes of Rapid7"
                },
                {
                    "lang": "en",
                    "type": "analyst",
                    "user": "00000000-0000-4000-9000-000000000000",
                    "value": "Caitlin Condon of Rapid7"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "user": "00000000-0000-4000-9000-000000000000",
                    "value": "Fryco of Frycos Security"
                }
            ],
            "datePublic": "2023-02-01T15:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2."
                        }
                    ],
                    "value": "Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2."
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-502",
                            "description": "CWE-502 Deserialization of Untrusted Data",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "9974b330-7714-4307-a722-5648477acda7",
                "shortName": "rapid7",
                "dateUpdated": "2023-04-10T19:06:33.125Z"
            },
            "references": [
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1"
                },
                {
                    "tags": [
                        "media-coverage"
                    ],
                    "url": "https://infosec.exchange/@briankrebs/109795710941843934"
                },
                {
                    "tags": [
                        "third-party-advisory"
                    ],
                    "url": "https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/"
                },
                {
                    "tags": [
                        "third-party-advisory"
                    ],
                    "url": "https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis"
                },
                {
                    "tags": [
                        "exploit"
                    ],
                    "url": "https://github.com/rapid7/metasploit-framework/pull/17607"
                },
                {
                    "tags": [
                        "media-coverage"
                    ],
                    "url": "https://duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mft"
                },
                {
                    "tags": [
                        "third-party-advisory"
                    ],
                    "url": "https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Fortra GoAnywhere MFT License Response Servlet Command Injection",
            "x_generator": {
                "engine": "Vulnogram 0.1.0-dev"
            }
        },
        "adp": [
            {
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2024-08-02T05:17:50.355Z"
                },
                "title": "CVE Program Container",
                "references": [
                    {
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1"
                    },
                    {
                        "tags": [
                            "media-coverage",
                            "x_transferred"
                        ],
                        "url": "https://infosec.exchange/@briankrebs/109795710941843934"
                    },
                    {
                        "tags": [
                            "third-party-advisory",
                            "x_transferred"
                        ],
                        "url": "https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/"
                    },
                    {
                        "tags": [
                            "third-party-advisory",
                            "x_transferred"
                        ],
                        "url": "https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis"
                    },
                    {
                        "tags": [
                            "exploit",
                            "x_transferred"
                        ],
                        "url": "https://github.com/rapid7/metasploit-framework/pull/17607"
                    },
                    {
                        "tags": [
                            "media-coverage",
                            "x_transferred"
                        ],
                        "url": "https://duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mft"
                    },
                    {
                        "tags": [
                            "third-party-advisory",
                            "x_transferred"
                        ],
                        "url": "https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html"
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    }
                ]
            },
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 7.2,
                            "attackVector": "NETWORK",
                            "baseSeverity": "HIGH",
                            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "HIGH",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2023-02-07T00:00:00+00:00",
                                "options": [
                                    {
                                        "Exploitation": "active"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3",
                                "id": "CVE-2023-0669"
                            }
                        }
                    },
                    {
                        "other": {
                            "type": "kev",
                            "content": {
                                "dateAdded": "2023-02-10",
                                "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-0669"
                            }
                        }
                    }
                ],
                "references": [
                    {
                        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-0669",
                        "tags": [
                            "government-resource"
                        ]
                    }
                ],
                "timeline": [
                    {
                        "time": "2023-02-10T00:00:00.000Z",
                        "lang": "en",
                        "value": "CVE-2023-0669 added to CISA KEV"
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-06T03:55:37.886Z"
                }
            }
        ]
    }
}