Accellion Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Accellion products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

4

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Accellion KEVs Added by Year

Loading...

4 Accellion KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-27103

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

Confirmed In CISA 03 Nov 2021
CVE-2021-27101

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is...

Confirmed In CISA 03 Nov 2021
CVE-2021-27102

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

Confirmed In CISA 03 Nov 2021
CVE-2021-27104

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is...

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-918 — Server-Side Request Forgery (SSRF) 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology