CVE-2021-27103KEV · OVERDUE

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Critical · published February 16, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 95.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
11%
Percentile
95.7
In the wild
Confirmed
What it is

🚨 A crafted POST request can unleash serious chaos in Accellion FTA versions 9_12_411 and earlier! Imagine a delivery driver dropping off packages anywhere they please — that’s the danger of this SSRF vulnerability! 🔥 Think of this SSRF vulnerability like a splashy buffet that lets anyone grab food from the kitchen without checking if they have permission — attackers can access internal services and data without a second glance! This vulnerability could allow attackers to reach sensitive internal resources and perform unauthorized actions, potentially leading to data leakage or unauthorized system access. It's absolutely devastating because they could exploit internal services while remaining undetected!

Put simply

Think of this SSRF vulnerability like a splashy buffet that lets anyone grab food from the kitchen without checking if they have permission — attackers can access internal services and data without a second glance! The SSRF vulnerability in Accellion FTA allows attackers to send a specially crafted POST request to wmProgressstat.html, resulting in unauthorized access to internal resources. This means a simple request could turn into a gateway for attackers to exploit sensitive data or services.

What to do

This vulnerability could allow attackers to reach sensitive internal resources and perform unauthorized actions, potentially leading to data leakage or unauthorized system access. It's absolutely devastating because they could exploit internal services while remaining undetected! Immediately upgrade to version FTA_9_12_416 or later to patch this vulnerability. Additionally, review and sanitize any user inputs to prevent future exploit attempts. It's crucial to audit your system and ensure no sensitive endpoints are exposed! This is fixable! Upgrade now, and you'll have your defenses up in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.11315 · 95.7th percentile
Published
2021-02-16T20:12Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 16 FEB 20:12Z
    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html
    cvelistv5