ZeroHour

CVE-2021-27101

KEV ransomwarelarge1

Unauthenticated SQL Injection in Accellion FTA via Crafted Host Header

CISA: Accellion FTA SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
6%p93
Published
()
KEV added
AI analysis

Accellion FTA (File Transfer Appliance) versions FTA_9_12_370 and earlier contain a critical (CVSS 3.1: 9.8) SQL injection vulnerability in the document_root.html web page. An unauthenticated remote attacker triggers it by sending an HTTP request to document_root.html with a crafted Host header, which is passed into SQL queries without sanitization. Successful exploitation gives unauthenticated access to the appliance's database to read, modify, or delete stored data, and the flaw was used in the wild chained with other FTA bugs (including the CVE-2021-27102 DEWMODE web shell) to execute code, exfiltrate files, and extort dozens of organizations, most famously Qualys. Any organization still running a legacy Accellion FTA appliance is exposed, since exploitation requires no authentication or user interaction. Exploitation is confirmed in the wild: the vulnerability is in CISA's KEV catalog (added 2021-11-03) with known ransomware use, and it was cited in the joint US/UK/Australia advisory on routinely exploited vulnerabilities.

What to do: Upgrade FTA to FTA_9_12_380 or later per vendor instructions, noting that FTA is an end-of-life product and Accellion has urged migration to Kiteworks. Given confirmed in-the-wild exploitation with ransomware use, hunt for indicators of compromise on the appliance, including the DEWMODE web shell, unexpected database records, and anomalous outbound or HTTP traffic. If patching cannot be done immediately, limit the appliance's internet exposure as much as possible until the fix is applied.

Affected
Accellion FTA (File Transfer Appliance)FTA_9_12_370 and earlier; fixed in FTA_9_12_380 and later
Estimated exposure
large≈100k–1M users via hundreds-to-thousands of legacy FTA appliances (precise count unknown) — Accellion FTA was a legacy on-premises file-transfer appliance deployed at large enterprises, universities, and government agencies, each typically serving hundreds to thousands of users, and public reporting on the 2021 Clop data-theft…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

CISA Known Exploited Vulnerability
Affected
Accellion FTA
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
accellion
Products
fta
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news