HIGH

CVE-2021-27102

Accellion Fta 2021-02-16 CVSS v3.1
CVSS
7.8
KEV

Description

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

Summary dbcve.org

OS command injection vulnerability in Accellion File Transfer Appliance allows execution of operating system commands through local web service calls in versions 9_12_411 and earlier.

Mitigation

Upgrade Accellion FTA to version FTA_9_12_416 or later to remediate the command execution vulnerability.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

3.65%
Probability of exploitation in next 30 days
89.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE