PT-2021-2476 · Accellion · Accellion Fta

Published

2021-02-16

·

Updated

2025-11-03

·

CVE-2021-27104

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accellion FTA versions 9 12 370 and earlier
Description The issue is related to OS command injection in Accellion FTA, allowing an attacker to execute arbitrary commands and gain unauthorized access to protected information by sending specially crafted POST requests to various admin endpoints.
Recommendations For Accellion FTA versions 9 12 370 and earlier, update to version FTA 9 12 380 or later to resolve the issue. As a temporary workaround, consider restricting access to admin endpoints to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01843
CVE-2021-27104

Affected Products

Accellion Fta