Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to patched version.
Workaround
Restrict access to Admin Client.
References
History
Tue, 21 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data. | |
| Title | Encryption vulnerable to brute-force decryption in GoAnywhere MFT | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-04-21T19:33:03.005Z
Reserved: 2025-02-11T23:19:04.818Z
Link: CVE-2025-1241
No data.
Status : Awaiting Analysis
Published: 2026-04-21T15:16:35.320
Modified: 2026-04-21T16:20:24.180
Link: CVE-2025-1241
No data.
OpenCVE Enrichment
No data.
Weaknesses