Accellion SFTP Remote Code Execution Vulnerability
BID:67606
Info
Accellion SFTP Remote Code Execution Vulnerability
| Bugtraq ID: | 67606 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2014 12:00AM |
| Updated: | May 26 2014 12:00AM |
| Credit: | Thomas Hibbert |
| Vulnerable: |
Accellion File Transfert FTA_7_0135 Accellion File Transfer 8.0.562 Accellion File Transfer FTA_8_0_105 Accellion File Transfer FTA_7_0_296 Accellion File Transfer FTA_7_0_259 Accellion File Transfer FTA_7_0_189 Accellion File Transfer FTA_7_0_178 Accellion File Transfer FTA_7_0_135 Accellion File Transfer 7_0_135 |
| Not Vulnerable: | |
Discussion
Accellion SFTP Remote Code Execution Vulnerability
Accellion SFTP is prone to remote code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application.
This issue affects Accellion File Transfer Appliance prior to FTA_9_8_70.
Accellion SFTP is prone to remote code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application.
This issue affects Accellion File Transfer Appliance prior to FTA_9_8_70.
Exploit / POC
Accellion SFTP Remote Code Execution Vulnerability
An attacker can exploit this issue using readily available tools.
The researcher of this issue has demonstrated a proof-of-concept code. Please see the references for more information.
An attacker can exploit this issue using readily available tools.
The researcher of this issue has demonstrated a proof-of-concept code. Please see the references for more information.
Solution / Fix
Accellion SFTP Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.