CVE-2021-27102
CVE-2021-27102
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 3.7%KEV simPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Feb 2021Published on NVD
03 Nov 2021Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short
Accellion FTA versions up to 9.12.411 have a flaw that allows attackers to run operating system commands through a local web service, potentially giving them full control of the affected system.
Technical detail
CWE-78 OS Command Injection vulnerability in Accellion FTA ≤9.12.411 allows unauthenticated or low-privileged local attackers to execute arbitrary OS commands via improper input validation in a local web service endpoint. Successful exploitation enables remote code execution with system privileges.
Summary generated and translated by AI from the official description.
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →