Beveiligingsadvies

CVE-2025-8148

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-05 20:56:05
Laatst bijgewerkt 2025-12-05 21:48:44
Toegewezen door Fortra
CVSS-score 4.2
Status PUBLISHED

Beschrijving

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.