Accellion: community verdicts
4 notable / known-exploited Accellion CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Accellion CVE, see NVD ↗.
- CVE-2021-27104CRIT 9.8KEVEPSS 56%
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
- CVE-2021-27103CRIT 9.8KEVEPSS 11%
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
- CVE-2021-27101CRIT 9.8KEVEPSS 6%
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
- CVE-2021-27102HIGH 7.8KEVEPSS 4%
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.