Early Access — Mondoo Vulnerability Intelligence is currently in preview.
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
Exploitability
AV:NAC:HPR:LUI:NScope
S:UImpact
C:LI:LA:N4.2/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NAccess Control
Configuration