CVE-2021-27103
KEV ransomwaremoderateServer-Side Request Forgery (SSRF) in Accellion FTA File Transfer Appliance
CISA: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-27103 is a server-side request forgery vulnerability (CWE-918) in Accellion's legacy File Transfer Appliance (FTA), rated critical (CVSS 3.1: 9.8) because it is reachable over the network with no authentication or user interaction required. It is triggered by sending a crafted POST request to the wmProgressstat.html endpoint, causing the appliance to issue attacker-controlled requests that can be used to reach and interact with internal services. In the known exploitation chain, attackers used FTA flaws, including this SSRF, as an entry point to deploy the DEWMODE web shell, exfiltrate data, and deploy Clop ransomware, producing the widespread extortion and supply-chain impact seen in the 2021 Accellion campaign. Any organization running Accellion FTA 9_12_411 or earlier is affected, typically internet-facing appliances used for large file transfers in sectors such as healthcare, education, and government. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS estimates an 11.4% probability of exploitation in the next 30 days (96th percentile).
What to do: Apply the vendor update per CISA's required action: upgrade to FTA_9_12_416 or later, which also addresses the related 2021 FTA SSRF flaws; if the legacy appliance is end-of-life, plan migration to a supported transfer platform. Hunt for compromise by reviewing access logs for crafted POST requests to wmProgressstat.html and other FTA endpoints, checking for the DEWMODE web shell, and looking for unusual outbound transfers. As an interim mitigation, restrict internet exposure of the appliance to only required peers.
| Accellion FTA | FTA 9_12_411 and earlier (fixed in FTA_9_12_416 and later) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
- Affected
- Accellion FTA
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- accellion
- Products
- fta
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H