← back
CVE-2021-27102

CVE-2021-27102

CVSS 7.8 HIGHEPSS 3.7%● KEVCWE-78
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 3.7%KEV simPoC Nuclei Metasploit Patch
Lifecycle
16 Feb 2021Published on NVD
03 Nov 2021Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

Accellion FTA versions up to 9.12.411 have a flaw that allows attackers to run operating system commands through a local web service, potentially giving them full control of the affected system.

Technical detail

CWE-78 OS Command Injection vulnerability in Accellion FTA ≤9.12.411 allows unauthenticated or low-privileged local attackers to execute arbitrary OS commands via improper input validation in a local web service endpoint. Successful exploitation enables remote code execution with system privileges.

Summary generated and translated by AI from the official description.
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →