First published: Tue Feb 16 2021(Updated: )
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion FTA | <=9_12_370 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27104 is a vulnerability in Accellion FTA (File Transfer Appliance) that allows OS command injection through a crafted POST request to various admin endpoints.
CVE-2021-27104 has a severity rating of critical with a CVSS score of 9.8.
Accellion FTA versions up to and including 9_12_370 are affected by CVE-2021-27104.
To fix CVE-2021-27104, upgrade to version FTA_9_12_380 or later of Accellion FTA.
The Common Weakness Enumeration (CWE) numbers associated with CVE-2021-27104 are CWE-77 and CWE-78.