CVE-2009-4648: High severity Accellion Secure File Transfer Appliance vulnerability
Accellion Secure File Transfer Appliance before 80105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --filemove action in /usr/local/bin/admin.pl, or a hard link attack in (2) chmod or (3) a certain cp command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4648?
CVE-2009-4648 is considered a critical vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2009-4648?
To fix CVE-2009-4648, update the Accellion Secure File Transfer Appliance to version 8_0_105 or later.
Who is affected by CVE-2009-4648?
CVE-2009-4648 affects multiple versions of the Accellion Secure File Transfer Appliance prior to 8_0_105.
What kind of exploit is associated with CVE-2009-4648?
CVE-2009-4648 allows local administrators to execute arbitrary commands with elevated permissions.
Is there a workaround for CVE-2009-4648?
There are no known workarounds for CVE-2009-4648; upgrading to the fixed version is recommended.