CVE-2021-27102KEV · OVERDUE

Accellion FTA OS Command Injection Vulnerability

High · published February 16, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 88.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.8
EPSS
4%
Percentile
88.7
In the wild
Confirmed
What it is

🚨 A sneaky OS command execution vulnerability lurks in Accellion FTA versions 9_12_411 and earlier, and it’s already been exploited! 🔥 Think of it like a pizza delivery service that accepts any order without confirming if it’s actually from a customer — an attacker could order anything they want from your server just by calling the right local service! If exploited, an attacker could run arbitrary commands on the server, allowing them to access sensitive data, modify files, or even take full control of your system. This could lead to a catastrophic data breach or service disruption, putting your organization at serious risk!

Put simply

Think of it like a pizza delivery service that accepts any order without confirming if it’s actually from a customer — an attacker could order anything they want from your server just by calling the right local service! This vulnerability arises from inadequate validation of web service calls, allowing local OS commands to be executed without proper authorization. This situation grants attackers access to execute commands at the operating system level.

What to do

If exploited, an attacker could run arbitrary commands on the server, allowing them to access sensitive data, modify files, or even take full control of your system. This could lead to a catastrophic data breach or service disruption, putting your organization at serious risk! Immediately upgrade to Accellion FTA version 9_12_416 or later to close this security hole. Additionally, review server configurations to ensure strict validation of service calls is in place and monitor for any suspicious activity. Don’t wait — act now! You've got this! Follow these steps to secure your system and earn your security hero badge! 🦸

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.03624 · 88.7th percentile
Published
2021-02-16T20:07Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 16 FEB 20:07Z
    Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call
    cvelistv5