EXPOSURES › CVE-2023-0669
CVE-2023-0669
CRITICAL ⌖ ON CISA KEV · EXPLOITEDFortra GoAnywhere MFT suffered a pre-authentication remote code execution vulnerability due to deserializing attacker-controlled objects in the License Response Servlet.
The vulnerability allowed remote attackers to execute arbitrary code without authentication, enabling ransomware deployment and data exfiltration. DIB organizations must patch this critical flaw immediately and verify their MFT solutions for similar deserialization risks, as it directly impacts compliance with NIST 800-171 requirements for system integrity and access control.
Shame score — A pre-authentication RCE in a widely deployed MFT product linked to ransomware attacks demonstrates severe negligence and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.