Skip to content
COOEY

EXPOSURES › CVE-2021-27101

CVE-2021-27101

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27101 ↗
◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatcheddata-breach

Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.

A SQL injection flaw in Accellion FTA allowed attackers to extract data via a manipulated host header, resulting in significant data breaches and subsequent ransomware attacks. DIB organizations utilizing FTA face compliance risks (CMMC, NIST 800-171) and potential financial penalties; immediate remediation and incident response are critical.

Shame score — The vulnerability's exploitation in ransomware attacks and the widespread impact on DIB organizations demonstrate a significant failure in secure coding practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; only technical facts and catalog listings.
cooey ↗ neutral +0.00
Neutral; technical fact only.
"Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html."
SentinelOne ↗ neutral +0.00
Neutral; no mention of Accellion or CVE-2021-27101.
www.cvefind.com ↗ neutral +0.00
Neutral; no mention of Accellion or CVE-2021-27101.
CISA ↗ neutral +0.00
Neutral; no mention of Accellion or CVE-2021-27101.
cvefeed.io ↗ neutral +0.00
Neutral; no mention of Accellion or CVE-2021-27101.
app.opencve.io ↗ neutral +0.00
Neutral; no mention of Accellion or CVE-2021-27101.
NVD ↗ neutral +0.00
Neutral; no mention of Accellion or CVE-2021-27101.
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Kiteworks Federal Cloud
Accellion USA, LLC.
Authorized