CVE-2025-3871 - CVE House
Back to Database
Status published Medium CVE-2025-3871

Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier

Vulnerability Description

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3871

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

GoAnywhere MFT
Vulnerable Versions:
0

Timeline

Official Publish: July 16th, 2025
Last Modified: July 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)