Back to CVE List

CVE-2025-14362

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Vulnerability Description

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-307
Source
NVD
Vendor
Fortra
Product
GoAnywhere MFT

External References

Discussion (0)

Add Comment

No comments yet. Be the first!