CRITICAL

CVE-2021-27104

Accellion Fta 2021-02-16 CVSS v3.1
CVSS
9.8
KEV

Description

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

Summary dbcve.org

OS command injection vulnerability in Accellion FTA versions 9_12_370 and earlier allowing remote attackers to execute arbitrary operating system commands via crafted POST requests to admin endpoints.

Mitigation

Upgrade to FTA_9_12_380 or later; if immediate patching is not feasible, restrict network access to admin interfaces to trusted networks only and implement monitoring for indicators of compromise.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

56.69%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE