Executive brief
Accellion FTA contains an OS command injection vulnerability that can be exploited via a local web service call. Successful exploitation allows an attacker to execute arbitrary commands on the underlying operating system.
Affected products
- Accellion FTA 9_12_411 and earlier
Timeline
- 2021-02-16: disclosed: NVD Published Date
- 2021-02-19: patched: NVD assessment and fix version FTA_9_12_416 identified
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog