CVE-2021-27104: Accellion FTA OS Command Injection Vulnerability
Accellion FTA 912370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA912380 and later.
Other sources
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Accellion File Transfer Applianceto a version that resolves this vulnerability.Fixed in FTA_9_12_380
Event History
Frequently Asked Questions
What is CVE-2021-27104?
CVE-2021-27104 is a vulnerability in Accellion FTA (File Transfer Appliance) that allows OS command injection through a crafted POST request to various admin endpoints.
What is the severity of CVE-2021-27104?
CVE-2021-27104 has a severity rating of critical with a CVSS score of 9.8.
Which version of Accellion FTA is affected by CVE-2021-27104?
Accellion FTA versions up to and including 9_12_370 are affected by CVE-2021-27104.
How can I fix CVE-2021-27104?
To fix CVE-2021-27104, upgrade to version FTA_9_12_380 or later of Accellion FTA.
What is the Common Weakness Enumeration (CWE) number associated with CVE-2021-27104?
The Common Weakness Enumeration (CWE) numbers associated with CVE-2021-27104 are CWE-77 and CWE-78.