ZeroHour

CVE-2021-27102

KEV ransomwaremoderate

OS Command Injection in Accellion FTA Exploited in Clop Extortion Attacks

CISA: Accellion FTA OS Command Injection Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2021-27102 is an OS command injection flaw (CWE-78) in Accellion's legacy File Transfer Appliance (FTA) that permits operating-system command execution through a call to a local web service in FTA 9_12_411 and earlier. An attacker who can invoke that service can run arbitrary commands with high impact on the appliance's confidentiality, integrity, and availability (CVSS 3.1 base 7.8, local vector, low privileges, no user interaction); in the widely reported late-2020/early-2021 campaign, this flaw was exploited alongside other FTA zero-days and the DEWMODE web shell to steal data from organizations using the appliance. Any organization running Accellion FTA 9_12_411 or earlier, typically enterprises and government agencies using the on-prem appliance for secure large-file transfer, is affected. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, EPSS assigns a 3.7% 30-day exploitation probability (89th percentile), and related reporting ties it to the Clop data-theft extortion campaign, including the breach of cybersecurity firm Qualys. The vulnerability is fixed in FTA_9_12_416 and later.

What to do: Upgrade all FTA appliances to FTA_9_12_416 or later per vendor instructions, as required by the CISA KEV listing, and given FTA's legacy status consider migration to the vendor's current platform. Hunt for prior compromise, since the associated campaign deployed the DEWMODE web shell, by reviewing web-server and process logs on the appliance and checking for unexpected web shells, and keep the FTA web interface off the public internet until patched.

Affected
Accellion FTA (File Transfer Appliance)FTA 9_12_411 and earlier; fixed in FTA_9_12_416 and later
Estimated exposure
moderatelow thousands of on-prem FTA appliances worldwide, likely serving tens of thousands of enterprise users — Order-of-magnitude deployment-pattern estimate: FTA was a niche legacy on-prem appliance rather than mass-market software, with a limited enterprise install base (low thousands of internet-exposed FTA hosts in public scan data during the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

CISA Known Exploited Vulnerability
Affected
Accellion FTA
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
accellion
Products
fta
Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news