CVE-2021-27101
KEV ransomwarelarge1Unauthenticated SQL Injection in Accellion FTA via Crafted Host Header
CISA: Accellion FTA SQL Injection Vulnerability
Accellion FTA (File Transfer Appliance) versions FTA_9_12_370 and earlier contain a critical (CVSS 3.1: 9.8) SQL injection vulnerability in the document_root.html web page. An unauthenticated remote attacker triggers it by sending an HTTP request to document_root.html with a crafted Host header, which is passed into SQL queries without sanitization. Successful exploitation gives unauthenticated access to the appliance's database to read, modify, or delete stored data, and the flaw was used in the wild chained with other FTA bugs (including the CVE-2021-27102 DEWMODE web shell) to execute code, exfiltrate files, and extort dozens of organizations, most famously Qualys. Any organization still running a legacy Accellion FTA appliance is exposed, since exploitation requires no authentication or user interaction. Exploitation is confirmed in the wild: the vulnerability is in CISA's KEV catalog (added 2021-11-03) with known ransomware use, and it was cited in the joint US/UK/Australia advisory on routinely exploited vulnerabilities.
What to do: Upgrade FTA to FTA_9_12_380 or later per vendor instructions, noting that FTA is an end-of-life product and Accellion has urged migration to Kiteworks. Given confirmed in-the-wild exploitation with ransomware use, hunt for indicators of compromise on the appliance, including the DEWMODE web shell, unexpected database records, and anomalous outbound or HTTP traffic. If patching cannot be done immediately, limit the appliance's internet exposure as much as possible until the fix is applied.
| Accellion FTA (File Transfer Appliance) | FTA_9_12_370 and earlier; fixed in FTA_9_12_380 and later |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
- Affected
- Accellion FTA
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- accellion
- Products
- fta
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H