The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
References
| Link | Resource |
|---|---|
| https://fortra.com/security/advisories/product-security/FI-2026-002 | Vendor Advisory |
Configurations
History
23 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* | |
| First Time |
Fortra
Fortra goanywhere Managed File Transfer |
|
| References | () https://fortra.com/security/advisories/product-security/FI-2026-002 - Vendor Advisory |
21 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 15:16
Updated : 2026-04-23 14:16
NVD link : CVE-2025-14362
Mitre link : CVE-2025-14362
CVE.ORG link : CVE-2025-14362
JSON object : View
Products Affected
fortra
- goanywhere_managed_file_transfer
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
