CVE-2021-27102
CVE-2021-27102
In short
Accellion FTA versions up to 9.12.411 have a flaw that allows attackers to run operating system commands through a local web service, potentially giving them full control of the affected system.
Technical detail
CWE-78 OS Command Injection vulnerability in Accellion FTA ≤9.12.411 allows unauthenticated or low-privileged local attackers to execute arbitrary OS commands via improper input validation in a local web service endpoint. Successful exploitation enables remote code execution with system privileges.
Summary generated and translated by AI from the official description.
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →