CVE-2021-27103: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
Accellion FTA 912411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA912416 and later.
Other sources
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Accellion File Transfer Applianceto a version that resolves this vulnerability.Fixed in FTA_9_12_416
Event History
Frequently Asked Questions
What is CVE-2021-27103?
CVE-2021-27103 is a server-side request forgery (SSRF) vulnerability in Accellion FTA that can be exploited by sending a crafted POST request.
How does CVE-2021-27103 affect Accellion FTA?
CVE-2021-27103 affects Accellion FTA by allowing an attacker to perform server-side request forgery (SSRF) attacks.
What is the severity of CVE-2021-27103?
CVE-2021-27103 has a severity rating of critical, with a CVSS score of 9.8.
How can CVE-2021-27103 be exploited?
CVE-2021-27103 can be exploited by sending a crafted POST request to wmProgressstat.html in Accellion FTA.
Is there a fix available for CVE-2021-27103?
Accellion has released patches to address the server-side request forgery (SSRF) vulnerability in FTA.