CRITICAL

CVE-2021-27103

Accellion Fta 2021-02-16 CVSS v3.1
CVSS
9.8
KEV

Description

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

Summary dbcve.org

Accellion FTA versions 9_12_411 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability in the wmProgressstat.html endpoint. Attackers can craft malicious POST requests to cause the FTA server to make arbitrary HTTP requests to internal or external resources, potentially exposing internal services, metadata endpoints, or enabling further reconnaissance and attacks.

Mitigation

Upgrade Accellion FTA to version FTA_9_12_416 or later to remediate this vulnerability. If immediate upgrading is not possible, implement network segmentation to restrict the FTA server's ability to connect to sensitive internal resources.

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

11.41%
Probability of exploitation in next 30 days
95.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE