Executive brief
Accellion FTA is vulnerable to OS command injection via crafted POST requests to various administrative endpoints. This allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system.
Affected products
- Accellion FTA 9_12_370 and earlier
Timeline
- 2021-02-16: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-17: other: CISA KEV due date for remediation