CVE-2025-1241
EUVD-2025-20953921.04.2026, 15:16
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortra | goanywhere_agents | 𝑥 < 2.2.0 |
| fortra | goanywhere_managed_file_transfer | 𝑥 < 7.10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration