{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-0204/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-0204/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-0204/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-0204/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-0204/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-0204"},"sightings":{"href":"/api/v1/sightings/cve-2024-0204"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-0204.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-0204\n\ninfo:\n  name: Fortra GoAnywhere MFT - Authentication Bypass\n  author: DhiyaneshDK\n  severity: critical\n  description: |\n    Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.\n  impact: |\n    Unauthenticated attackers can bypass authentication to create administrator accounts, leading to complete control over the GoAnywhere MFT system and access to all managed file transfers and sensitive data.\n  remediation: |\n    Upgrade to Fortra GoAnywhere MFT version 7.4.1 or later.\n  reference:\n    - https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml\n    - https://www.fortra.com/security/advisory/fi-2024-001\n    - https://github.com/horizon3ai/CVE-2024-0204/blob/main/CVE-2024-0204.py\n    - https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/\n    - http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2024-0204\n    cwe-id: CWE-425\n    epss-score: 0.95086\n    epss-percentile: 0.9986\n    cpe: cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: fortra\n    product: goanywhere_managed_file_transfer\n    shodan-query:\n      - http.favicon.hash:1484947000,1828756398,1170495932\n      - http.favicon.hash:1484947000\n    fofa-query:\n      - app=\"GoAnywhere-MFT\"\n      - icon_hash=1484947000\n      - icon_hash=1484947000,1828756398,1170495932\n      - app=\"goanywhere-mft\"\n    zoomeye-query: app=\"Fortra GoAnywhere-MFT\"\n  tags: packetstorm,cve,cve2024,auth-bypass,goanywhere,fortra,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"Create an administrator account\"\n          - \"goanywhere\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a0047304502206c6a9ea5add42aec73d596c9172de22bd933c6880a628dca017ad6d374214f40022100cd433a7a115fa25b0643684695497cda5b3042fa606f9da6715ebfea3881eab1:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2024-0204"}