Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
References
| Link | Resource |
|---|---|
| https://fortra.com/security/advisories/product-security/FI-2026-001 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-04-21 15:16
Updated : 2026-06-17 08:38
NVD link : CVE-2025-1241
Mitre link : CVE-2025-1241
CVE.ORG link : CVE-2025-1241
JSON object : View
Products Affected
fortra
- goanywhere_managed_file_transfer
- goanywhere_agents
microsoft
- windows
linux
- linux_kernel
apple
- macos
CWE
CWE-326
Inadequate Encryption Strength
