SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Fortra GoAnywhere MFT authentication bypass attempt
This rule looks for crafted HTTP requests containing path traversal sequences that allows for an authorization bypass and the ability to create an admin user in the Fortra GoAnywhere MFT product.
This rule looks for attempts to exploit a path traversal vulnerability in Fortra GoAnywhere MFT web applications.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2024-0204 |
Loading description
|