QID 731208

Date Published: 2024-02-28

QID 731208: Accellion File Transfer Appliance (FTA) Multiple Security Vulnerabilities (CVE-2021-27102,CVE-2021-27103)

Accellion File Transfer Appliance is a file transfer application that is used to share files.

CVE-2021-27102: FTA 9_12_411 and earlier is affected by OS command execution via a local web service call.
CVE-2021-27103: FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to an endpoint.

Affected Versions:
Accellion FTA versions 9_12_411 and earlier

Patch Versions:
Accellion FTA_version 9_12_416 and later

QID Detection Logic (Unauthenticated):
This QID detects Accellion File Transfer Appliance from WebUI.

Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary command on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please contact vendor Accellion for patch details.

    CVEs related to QID 731208

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-27102 URL Logo github.com/accellion/CVEs/blob/main/CVE-2021-27102.txt
    CVE-2021-27103 URL Logo github.com/accellion/CVEs/blob/main/CVE-2021-27103.txt