« Volver al listado

CVE-2025-14362

Estado: AnalizadaAlta (7.3)—

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/AC:L/PR:N permite ataque directo remoto. CWE-307 (límite de intentos ausente) posibilita fuerza bruta contra claves SSH. El acceso a cuenta valida (T1078) y ejecución de comandos SFTP son consecuencias.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-14362",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-14362",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-21T19:33:27.357827Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
      "affectedData": [
        {
          "vendor": "Fortra",
          "product": "GoAnywhere MFT",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.10.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-21T15:16:35.207",
  "references": [
    {
      "url": "https://fortra.com/security/advisories/product-security/FI-2026-002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "df4dee71-de3a-4139-9588-11b62fe6c0ff"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
      "description": [
        {
          "lang": "en",
          "value": "CWE-307"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force."
    },
    {
      "lang": "es",
      "value": "El límite de intentos de inicio de sesión no se aplica en el servicio SFTP de GoAnywhere MFT de Fortra anterior a la versión 7.10.0 si el usuario web al que se intenta iniciar sesión está configurado para iniciar sesión con una clave SSH, lo que hace que la clave SSH sea vulnerable a ser adivinada mediante fuerza bruta."
    }
  ],
  "lastModified": "2026-09-30T22:10:00.273",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EB6422D-7B12-41B3-BD42-5610C6C72524",
              "versionEndExcluding": "7.10.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "df4dee71-de3a-4139-9588-11b62fe6c0ff"
}