CVE-2024-9945: Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0
Published Dec 13, 2024
·Updated
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.
Affected Software
1 affected component
Fortra GoAnywhere MFT<7.7.0
Remediation
Information
Upgrade to GoAnywhere 7.7.0 or higher.
Event History
Dec 13, 2024
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9945?
CVE-2024-9945 is classified as an information disclosure vulnerability that poses a risk of unauthorized access to sensitive resources.
2
How do I fix CVE-2024-9945?
To fix CVE-2024-9945, update the Fortra GoAnywhere MFT application to version 7.7.0 or later.
3
What products are affected by CVE-2024-9945?
CVE-2024-9945 affects Fortra GoAnywhere MFT versions prior to 7.7.0.
4
What kind of information is at risk due to CVE-2024-9945?
CVE-2024-9945 can lead to external access to resources located in certain admin root folders.
5
Who is responsible for addressing CVE-2024-9945?
Users of Fortra GoAnywhere MFT are responsible for implementing the necessary updates to mitigate CVE-2024-9945.