Junglewise Threat Intelligence

CVE-2021-27103: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

CVE-2021-27103 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Accellion FTA. Vendors: Accellion.

Executive brief

Accellion FTA contains a server-side request forgery (SSRF) vulnerability that can be triggered via a crafted POST request to wmProgressstat.html. This vulnerability has been observed being exploited in the wild.

Affected products

  • Accellion FTA 9_12_411 and earlier

Timeline

  • 2021-02-16: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: patched: Due date for remediation per CISA KEV catalog; fixed in FTA_9_12_416

Related threats