Skip to content
COOEY

EXPOSURES › CVE-2021-27102

CVE-2021-27102

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27102 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wilddata-breachunpatched

Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.

A critical OS command injection vulnerability in Accellion FTA allowed attackers to execute arbitrary commands, leading to data exfiltration and likely ransomware deployment. DIB organizations using FTA, or vendors incorporating it, face significant compliance risks (NIST 800-171) and potential legal repercussions; immediate remediation and thorough supply chain assessment are essential.

Shame score — The vulnerability's exploitation in ransomware attacks and widespread use within the DIB demonstrates a significant failure in secure development practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; sources are CVE databases and aggregators with no commentary on vendor handling.
cooey ↗ neutral +0.00
Neutral; NVD entry states facts without sentiment.
"Accellion FTA contains an OS command injection vulnerability exploited via a local web service call."
cve.akaoma.com ↗ neutral +0.00
Neutral; CVE aggregator page with no vendor commentary.
www.cvefind.com ↗ neutral +0.00
Neutral; CVE database site with no vendor commentary.
app.opencve.io ↗ neutral +0.00
Neutral; CVE database site with no vendor commentary.
SentinelOne ↗ neutral +0.00
Neutral; Vendor security page with no CVE commentary.
cvefeed.io ↗ neutral +0.00
Neutral; CVE aggregator page with no vendor commentary.
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Kiteworks Federal Cloud
Accellion USA, LLC.
Authorized