Junglewise Threat Intelligence

CVE-2021-27102: Accellion FTA OS Command Injection Vulnerability

CVE-2021-27102 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Accellion FTA. Vendors: Accellion.

Executive brief

Accellion FTA contains an OS command injection vulnerability that can be exploited via a local web service call. Successful exploitation allows an attacker to execute arbitrary commands on the underlying operating system.

Affected products

  • Accellion FTA 9_12_411 and earlier

Timeline

  • 2021-02-16: disclosed: NVD Published Date
  • 2021-02-19: patched: NVD assessment and fix version FTA_9_12_416 identified
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats