RCE Zero Day in GoAnywhere MFT [CVE-2023-0669]
ID: 08b71b15-5bd8-5460-b5eb-4870f130fe21
STIX ID: report--08b71b15-5bd8-5460-b5eb-4870f130fe21
Feed Name: Censys Blog
An actively exploited pre-auth remote code execution vulnerability (CVE-2023-0669) in GoAnywhere MFT has been disclosed and linked to the Clop ransomware gang's claims of breaching many organizations; Censys found 330 internet-exposed admin consoles with roughly 267 appearing vulnerable. Multiple victims (Community Health Systems, Hitachi Energy, Hatch Bank, Rubrik, City of Toronto, Procter & Gamble, Saks Fifth Avenue, Crown Resorts, etc.) are named in reports; Fortra released an emergency patch (7.1.2) and the report urges immediate patching, removal of public exposure, and tighter admin access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
