---
id: CVE-2025-1241
title: "Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which\_allows admin users to brute-force decryption of data."
summary: "Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which\_allows admin users to brute-force decryption of data."
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-326
vendor: fortra
product: goanywhere_agents
affected:
  - goanywhere_agents < 2.2.0
  - goanywhere_managed_file_transfer < 7.10.0
patched:
  - goanywhere_agents 2.2.0
  - goanywhere_managed_file_transfer 7.10.0
published: '2026-04-21'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1241'
references:
  - url: 'https://fortra.com/security/advisories/product-security/FI-2026-001'
    label: df4dee71-de3a-4139-9588-11b62fe6c0ff
tags:
  - nvd
epss: 0.00127
epssPercentile: 0.02021
ingestedAt: '2026-09-30T22:27:27.764Z'
---

## Overview

Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.

## Affected

- `goanywhere_agents < 2.2.0`
- `goanywhere_managed_file_transfer < 7.10.0`

## Remediation

Upgrade past the affected range:

- `goanywhere_agents 2.2.0`
- `goanywhere_managed_file_transfer 7.10.0`
