{"cveID":"CVE-2023-0669","vendorProject":"Fortra","product":"GoAnywhere MFT","vulnerabilityName":"Fortra GoAnywhere MFT Remote Code Execution Vulnerability","dateAdded":"2023-02-10","shortDescription":"Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-03-03","knownRansomwareCampaignUse":"Known","notes":"This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch.;  https://nvd.nist.gov/vuln/detail/CVE-2023-0669","cwes":["CWE-502"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-0669","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This vulnerability is exploited through a cross-site request forgery (CSRF) flaw in GoAnywhere's license installation process. Attackers initiate this vulnerability by leveraging the absence of CSRF protection, allowing them to execute remote code without authentication. This enables them to compromise targeted systems, facilitating ransomware attacks and unauthorized access. This vulnerability has been actively exploited, leading to ransomware attacks by the Clop group. ","references":["https://www.darkreading.com/endpoint-security/massive-goanywhere-rce-exploit","https://www.darkreading.com/cyberattacks-data-breaches/fortra-discloses-critical-auth-bypass-vuln-in-goanywhere-mft","https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis","https://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-0669","technique":"T1210","technique_name_at_mapping":"Exploitation of Remote Services","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited through a cross-site request forgery (CSRF) flaw in GoAnywhere's license installation process. Attackers initiate this vulnerability by leveraging the absence of CSRF protection, allowing them to execute remote code without authentication. This enables them to compromise targeted systems, facilitating ransomware attacks and unauthorized access. This vulnerability has been actively exploited, leading to ransomware attacks by the Clop group. ","references":["https://www.darkreading.com/endpoint-security/massive-goanywhere-rce-exploit","https://www.darkreading.com/cyberattacks-data-breaches/fortra-discloses-critical-auth-bypass-vuln-in-goanywhere-mft","https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis","https://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-0669","technique":"T1486","technique_name_at_mapping":"Data Encrypted for Impact","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited through a cross-site request forgery (CSRF) flaw in GoAnywhere's license installation process. Attackers initiate this vulnerability by leveraging the absence of CSRF protection, allowing them to execute remote code without authentication. This enables them to compromise targeted systems, facilitating ransomware attacks and unauthorized access. This vulnerability has been actively exploited, leading to ransomware attacks by the Clop group. ","references":["https://www.darkreading.com/endpoint-security/massive-goanywhere-rce-exploit","https://www.darkreading.com/cyberattacks-data-breaches/fortra-discloses-critical-auth-bypass-vuln-in-goanywhere-mft","https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis","https://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1210","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation of Remote Services","name_at_mapping":"Exploitation of Remote Services","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":15,"has_detection_strategy":true},{"id":"T1486","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data Encrypted for Impact","name_at_mapping":"Data Encrypted for Impact","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":16,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}