CVE-2025-14362: GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortra GoAnywhere MFTto a version that resolves this vulnerability.Fixed in 7.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14362?
CVE-2025-14362 has been rated as a high severity vulnerability due to its potential for brute force attacks.
How do I fix CVE-2025-14362?
To fix CVE-2025-14362, upgrade to Fortra's GoAnywhere MFT version 7.10.0 or later.
What does CVE-2025-14362 affect?
CVE-2025-14362 affects the SFTP service of Fortra's GoAnywhere MFT prior to version 7.10.0.
What can attackers do with CVE-2025-14362?
Attackers can attempt to perform brute-force login attacks on the SFTP service under certain configurations.
Is CVE-2025-14362 a widespread issue?
Yes, CVE-2025-14362 could potentially affect any institution using vulnerable versions of Fortra's GoAnywhere MFT.