QID 731208
Date Published: 2024-02-28
QID 731208: Accellion File Transfer Appliance (FTA) Multiple Security Vulnerabilities (CVE-2021-27102,CVE-2021-27103)
Accellion File Transfer Appliance is a file transfer application that is used to share files.
CVE-2021-27102: FTA 9_12_411 and earlier is affected by OS command execution via a local web service call.
CVE-2021-27103: FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to an endpoint.
Affected Versions:
Accellion FTA versions 9_12_411 and earlier
Patch Versions:
Accellion FTA_version 9_12_416 and later
QID Detection Logic (Unauthenticated):
This QID detects Accellion File Transfer Appliance from WebUI.
Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary command on the target system.
Solution
Please contact vendor Accellion for patch details.
Vendor References
- CVE-2021-27102 -
github.com/accellion/CVEs/blob/main/CVE-2021-27102.txt - CVE-2021-27103 -
github.com/accellion/CVEs/blob/main/CVE-2021-27103.txt
CVEs related to QID 731208
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-27102 |
|
||
| CVE-2021-27103 |
|