Junglewise Threat Intelligence

CVE-2021-27104: Accellion FTA OS Command Injection Vulnerability

CVE-2021-27104 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Accellion FTA. Vendors: Accellion.

Executive brief

Accellion FTA is vulnerable to OS command injection via crafted POST requests to various administrative endpoints. This allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system.

Affected products

  • Accellion FTA 9_12_370 and earlier

Timeline

  • 2021-02-16: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: other: CISA KEV due date for remediation

Related threats