ZeroHour

CVE-2021-27103

KEV ransomwaremoderate

Server-Side Request Forgery (SSRF) in Accellion FTA File Transfer Appliance

CISA: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

CVSS 3.1
9.8 critical
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2021-27103 is a server-side request forgery vulnerability (CWE-918) in Accellion's legacy File Transfer Appliance (FTA), rated critical (CVSS 3.1: 9.8) because it is reachable over the network with no authentication or user interaction required. It is triggered by sending a crafted POST request to the wmProgressstat.html endpoint, causing the appliance to issue attacker-controlled requests that can be used to reach and interact with internal services. In the known exploitation chain, attackers used FTA flaws, including this SSRF, as an entry point to deploy the DEWMODE web shell, exfiltrate data, and deploy Clop ransomware, producing the widespread extortion and supply-chain impact seen in the 2021 Accellion campaign. Any organization running Accellion FTA 9_12_411 or earlier is affected, typically internet-facing appliances used for large file transfers in sectors such as healthcare, education, and government. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS estimates an 11.4% probability of exploitation in the next 30 days (96th percentile).

What to do: Apply the vendor update per CISA's required action: upgrade to FTA_9_12_416 or later, which also addresses the related 2021 FTA SSRF flaws; if the legacy appliance is end-of-life, plan migration to a supported transfer platform. Hunt for compromise by reviewing access logs for crafted POST requests to wmProgressstat.html and other FTA endpoints, checking for the DEWMODE web shell, and looking for unusual outbound transfers. As an interim mitigation, restrict internet exposure of the appliance to only required peers.

Affected
Accellion FTAFTA 9_12_411 and earlier (fixed in FTA_9_12_416 and later)
Estimated exposure
moderateon the order of a few thousand FTA appliance deployments, concentrated among legacy on-prem file-transfer users (100+ organizations confirmed compromised in… — Accellion FTA is a legacy on-prem file-transfer appliance with a limited installed base, and public internet scans and incident reporting around the 2021 Clop/FIN11 campaign showed only hundreds to low thousands of internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

CISA Known Exploited Vulnerability
Affected
Accellion FTA
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
accellion
Products
fta
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news