CVE-2021-27104KEV · OVERDUE

Accellion FTA OS Command Injection Vulnerability

Critical · published February 16, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 99.0th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
56%
Percentile
99.0
In the wild
Confirmed
What it is

🚨 A simple POST request can open the floodgates! The Accellion FTA has a critical command execution vulnerability that could let attackers seize control of your system like a burglar picking the lock on a front door! 🔥 This flaw is like a hotel that lets guests check in without proper ID. If someone crafty shows up and knows just the right details, they could easily access any room, including your valuables. It's all about trusting the wrong person with the keys! An attacker could execute arbitrary commands on your server, potentially leading to data breaches, unauthorized access, or even complete takeover. This vulnerability is absolutely devastating—if exploited, it could result in severe harm to your organization's reputation and security!

Put simply

This flaw is like a hotel that lets guests check in without proper ID. If someone crafty shows up and knows just the right details, they could easily access any room, including your valuables. It's all about trusting the wrong person with the keys! CVE-2021-27104 allows OS command execution via specially crafted POST requests to various admin endpoints in Accellion FTA versions 9_12_370 and earlier. The vulnerability arises from insufficient validation of user input, enabling attackers to run commands on the server directly.

What to do

An attacker could execute arbitrary commands on your server, potentially leading to data breaches, unauthorized access, or even complete takeover. This vulnerability is absolutely devastating—if exploited, it could result in severe harm to your organization's reputation and security! Immediately upgrade to Accellion FTA version 9_12_380 or later to patch this critical vulnerability. Review your system configurations and ensure that only authorized users have access to admin endpoints. It’s vital to audit your logs for any suspicious activities that may have occurred. 🛡️ You've got this! Follow these steps, and you'll secure your system in no time! 💪✨

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.56411 · 99.0th percentile
Published
2021-02-16T20:16Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 16 FEB 20:16Z
    Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints
    cvelistv5