PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-1241 Fortra CVE debrief

Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data. This vulnerability requires immediate attention from administrators to assess exposure and update decryption practices. The static IV usage enables admin users to potentially access sensitive data through brute-force decryption methods. Therefore, it is crucial to verify decryption practices and implement compensating controls where necessary.

Vendor
Fortra
Product
GoAnywhere MFT
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-21
Original CVE updated
2026-09-30
Advisory published
2026-04-21
Advisory updated
2026-09-30

Who should care

Admin users of GoAnywhere MFT and GoAnywhere Agents should assess exposure and prioritize verification of decryption practices. This includes reviewing current decryption methods, assessing the potential impact of brute-force decryption, and implementing compensating controls where necessary. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact

Why it matters

CVE-2025-1241 allows admin users to brute-force decryption of data in Fortra's GoAnywhere MFT and GoAnywhere Agents due to static IV usage, requiring verification and potential updates to decryption practices.

  • Admin users can brute-force decryption of data due to static IV usage.
  • Decryption practices require verification and potential updates.
  • Exposure assessment and compensating controls implementation are necessary.

Technical summary

The vulnerability in Fortra's GoAnywhere MFT and GoAnywhere Agents is due to the use of a static IV for encrypting values. This allows admin users to brute-force decryption of data, potentially leading to unauthorized access to sensitive information. The affected products are GoAnywhere MFT versions prior to 7.10.0 and GoAnywhere Agents versions prior to 2.2.0. Administrators must verify decryption practices and update systems to mitigate this vulnerability.

Defensive priority

Admin users should assess exposure and prioritize verification of decryption practices.

Recommended defensive actions

  • Admin users should verify decryption practices for GoAnywhere MFT and GoAnywhere Agents.
  • Review and update GoAnywhere MFT to version 7.10.0 or later and GoAnywhere Agents to version 2.2.0 or later.
  • Assess exposure and implement compensating controls for decryption practices.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but vendor advisory details are limited. The NVD entry confirms the vulnerability exists in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0. However, additional verification is required to assess the full scope of affected systems and to confirm the effectiveness of proposed mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-1241 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-1241

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-1241 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-1241

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://fortra.com/security/advisories/product-security/FI-2026-001

    df4dee71-de3a-4139-9588-11b62fe6c0ff - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.