CVE-2021-27101KEV · OVERDUE

Accellion FTA SQL Injection Vulnerability

Critical · published February 16, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 92.8th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
6%
Percentile
92.8
In the wild
Confirmed
What it is

🚨 A crafty Host header can unlock the SQL injection door in Accellion FTA, putting your data at risk! 🔥 Think of it like a restaurant reservation system where someone sneaks in a fake reservation under a different name. If the system doesn’t check properly, they can access restricted areas, just like your database could be compromised here. An attacker can exploit this vulnerability to run arbitrary SQL commands, potentially exposing sensitive data, manipulating records, or even taking down your entire database! Imagine not just losing your data but also leaking customer details, causing catastrophic consequences for your organization.

Put simply

Think of it like a restaurant reservation system where someone sneaks in a fake reservation under a different name. If the system doesn’t check properly, they can access restricted areas, just like your database could be compromised here. This SQL injection vulnerability occurs when a specially crafted Host header is processed by the document_root.html file, allowing an attacker to execute unauthorized SQL commands against the underlying database.

What to do

An attacker can exploit this vulnerability to run arbitrary SQL commands, potentially exposing sensitive data, manipulating records, or even taking down your entire database! Imagine not just losing your data but also leaking customer details, causing catastrophic consequences for your organization. To protect yourself, immediately upgrade to version FTA_9_12_380 or later. Additionally, review your configurations and implement strict input validation to catch any suspicious requests before they reach your database. You've got this! Fixing this vulnerability will enhance your security posture and keep your data safe. 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.05949 · 92.8th percentile
Published
2021-02-16T20:02Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 16 FEB 20:02Z
    Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html
    cvelistv5