CVE-2025-8148
BaseFortify
Publication date: 2025-12-05
Last updated on: 2025-12-08
Assigner: Fortra
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortra | goanywhere_mft | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Access Control issue in the SFTP service of Fortra's GoAnywhere MFT before version 7.9.0. It allows Web Users who have an Authentication Alias and a valid SSH key, but are supposed to be limited to Password authentication for SFTP, to bypass this restriction and still log in using their SSH key.
How can this vulnerability impact me? :
The vulnerability could allow unauthorized access to the SFTP service by users who should be restricted to password authentication only, potentially leading to unauthorized data access or modification. This could compromise confidentiality and integrity of data transferred via SFTP.