CVE-2017-8791: CRLF Injection
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. There is a home/seos/courier/login.html authparams CRLF attack vector.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8791?
CVE-2017-8791 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-8791?
To fix CVE-2017-8791, upgrade the Accellion FTA device to version FTA_9_12_180 or later.
3
What is the exploit type for CVE-2017-8791?
CVE-2017-8791 involves a CRLF injection vulnerability affecting authentication parameters.
4
Which versions of Accellion File Transfer Appliance are affected by CVE-2017-8791?
Versions of Accellion File Transfer Appliance prior to FTA_9_12_180 are affected by CVE-2017-8791.
5
What devices are impacted by CVE-2017-8791?
CVE-2017-8791 impacts Accellion FTA devices before version FTA_9_12_180.