[CIVN-2025-0219]Command Injection Vulnerability in Fortra GoAnywhere MFT
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Command Injection Vulnerability in Fortra GoAnywhere MFT
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Fortra GoAnywhere MFT versions prior to 7.8.4
Fortra GoAnywhere MFT (Sustain Release) prior to 7.6.3
Overview
A vulnerability has been reported in Fortra GoAnywhere MFT which could be exploited by an attacker to execute remote code on the targeted system.
Target Audience:
All end-user organizations who manage Fortra GoAnywhere MFT.
Risk Assessment:
High risk of server compromise and potential large-scale data exposure.
Impact Assessment:
Potential for full system takeover, operational disruption.
Description
Fortra GoAnywhere MFT is a managed file transfer (MFT) solution that automates and centralizes the exchange of sensitive data.
This vulnerability exists in the License Servlet component of Fortra GoAnywhere MFT due to improper handling and deserialization of untrusted license response data. A remote attacker could exploit this vulnerability by supplying a maliciously crafted license response signature or payload to the License Servlet, leading to arbitrary code execution on the target system.
Successful exploitation of the vulnerability could allow the attacker to completely compromise the affected MFT server.
Solution
Apply appropriate security updates as mentioned in the Fortra Security Updates
Vendor Information
Fortra
https://www.fortra.com/security/advisories/product-security/fi-2025-012
References
https://www.fortra.com/security/advisories/product-security/fi-2025-012
CVE Name
CVE-2025-10035
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjRYQYACgkQ3jCgcSdc
ys/S6w/+PVAfYTU6ZWBS0jddwkg/5LR3vtjhxIzBww1xMFHP57Iscf+cWh6syEPV
+Z3blJw0B8b30YUjRmlXQKgi+mho/hLvuOktxUqENtT+fnnuMS+OC1qfxl+Y3LTB
s3wF/alP2ssyTylEEwCcvmR2g7QblxYA17kFGMAaZI9b8PthlMR0NLRDvzqG8Zyh
Yk/+t63AYfU+ADpzpWuBal3aOdEswlbcglVaPoMti1+iee6AV6bwiT2EXfiVQ6/6
PgW+jHvva7G8ALMhm/h4iZMkiBwV5DU+TvBtZAzcRKZAa+1hLi7qRHo1jE5H3ok7
ulEOsy4TTlHe+qCsoj8TVBpsZiccAa/DBOZHHS1sgWIM0s4+jR1n8DSIl8Q6ncoH
nkEO9K1W9eVTmMtOn67AS8q842RmpWds4NuipLFuLH8Qkh9n9qsZudWGKVI5RHrI
wkrZb5mOQabVMJgMOMd0VLZCWRvE9XitkOckSeCSQDM+lP1tKCiMFP4tSA85e+sE
lmvmQguKDmDPtjBBOBHBCj5tozx6tCkJDAEhkG++AfVq1eeDD6fDuoIjuUA3hKx8
6J5zEJBEgtve+dSUfXOL54fCLq8iOcz8VeK/HCkMRCYmRVaLPMEsDsGAydTo44eI
gtchRZ4zzLNfC1ggGFdpYqocLxVb61sUrpjOShGeByGvkBVa0Is=
=yCdE
—–END PGP SIGNATURE—–