CVE-2021-27102: Accellion FTA OS Command Injection Vulnerability
Accellion FTA 912411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA912416 and later.
Other sources
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Accellion File Transfer Applianceto a version that resolves this vulnerability.Fixed in FTA_9_12_416
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-27102.
What is the title of this vulnerability?
The title of this vulnerability is Accellion FTA OS Command Injection Vulnerability.
What is the description of this vulnerability?
This vulnerability affects Accellion FTA 9_12_411 and earlier and allows for OS command execution via a local web service call.
What is the severity of CVE-2021-27102?
The severity of CVE-2021-27102 is high with a CVSS score of 7.8.
How do I fix CVE-2021-27102?
To fix CVE-2021-27102, upgrade to Accellion FTA version FTA_9_12_416 or later.