Encrypted values in Fortras GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Goanywhere_agents | Fortra | * | 2.2.0 (excluding) |
| Goanywhere_managed_file_transfer | Fortra | * | 7.10.0 (excluding) |