Listen to this Post
CVE-2024-0204 represents a severe authentication bypass vulnerability.
It impacts the Fortra GoAnywhere Managed File Transfer application.
The flaw resides in the administrative setup mechanism.
Unauthenticated remote attackers can exploit this weakness.
By sending a specially crafted HTTP request to the server.
An attacker can create a new administrative user account.
This bypasses all existing authentication controls completely.
The vulnerability stems from an insecure design flaw in initialization logic.
Specifically within the SetupWizard servlet or equivalent endpoint.
Which fails to properly validate if an admin user already exists.
Consequently, an external user can invoke administrative setup workflows.
Granting full administrative access to the backend dashboard.
Once administrative privileges are acquired, execution of system commands is possible.
This leads directly to remote code execution on the underlying host.
Attackers can upload malicious payloads or web shells.
Compromising the entire confidentiality and integrity of the system.
The vulnerability affects versions 7.4.1 and all prior versions.
Public exploit scripts emerged rapidly following initial disclosures.
Threat actors actively scanned the internet for vulnerable instances.
Exposing sensitive corporate data and internal file transfers.
Detection is possible by auditing unexpected user creation logs.
Or checking for unauthorized modifications in the administrative database.
CVSS score for this vulnerability is rated at 9.8 critical.
Remediation requires upgrading immediately to version 7.4.2 or later.
Alternatively, removing the offending initialization servlet mitigates risk.
Network segmentation and firewall restrictions also help limit exposure.
Restricting administrative interfaces to trusted internal IPs is crucial.
Automated threat intelligence platforms like Shodan track exposed instances.
Highlighting the urgency of rapid patching across global infrastructure.
Security teams must continuously monitor assets for such critical flaws.
DailyCVE Form:
Platform: Fortra GoAnywhere MFT
Version: Prior to 7.4.2
Vulnerability: Authentication Bypass
Severity: Critical
date: February 1 2024
Prediction: Already patched 2024
What Undercode Say
Showing bash commands and codes related to the blog
`curl -k [https://cvedb.shodan.io/cve/CVE-2024-0204](https://cvedb.shodan.io/cve/CVE-2024-0204)`
`curl -s [https://api.shodan.io/shodan/host/SEARCH_IP?key=API_KEY](https://api.shodan.io/shodan/host/SEARCH_IP?key=API_KEY)`
Exploit: (Educational Purposes!)
`python3 exploit.py –target [https://vulnerable-instance.local](https://vulnerable-instance.local) –user admin`
`POST /initialization/SetupWizard.xhtml HTTP/1.1`
`Host: target`
`Content-Type: application/x-www-form-urlencoded`
`action=createAdmin&username=hacker&password=password123`
Protection:
Upgrade GoAnywhere MFT to version 7.4.2 or higher.
Restrict administrative portal access to trusted internal networks only.
Monitor system logs for unauthorized user creation events.
Impact:
Complete system compromise and unauthorized administrative access.
Execution of arbitrary system commands and remote code execution.
Potential exposure of sensitive enterprise file transfers and data leaks.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

