Description
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
INFO
Published Date :
2026-04-21T14:14:08.492Z
Last Modified :
2026-04-21T19:33:35.079Z
Source :
Fortra
AFFECTED PRODUCTS
The following products are affected by CVE-2025-14362 vulnerability.
| Vendors | Products |
|---|---|
| Fortra |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-14362.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact