Description

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

INFO

Published Date :

2026-04-21T14:14:08.492Z

Last Modified :

2026-04-21T19:33:35.079Z

Source :

Fortra
AFFECTED PRODUCTS

The following products are affected by CVE-2025-14362 vulnerability.

Vendors Products
Fortra
  • Goanywhere Mft
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-14362.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact