CVE Tools

Description

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

In plain language

AI Act now

Accellion FTA up to FTA_9_12_370 can be tricked with a fake Host header to break into the database, so a typical small business running it should treat this as an urgent fix (resolved in FTA_9_12_380 and later).

Executive summary

CVE-2021-27101 is a SQL injection weakness in Accellion FTA (FTA_9_12_370 and earlier) triggered via a crafted Host header in a request to document_root.html; it has been confirmed in real-world ransomware campaigns and listed in CISA KEV.

If affected, business impact
Database and file data theftRansomware risk through takeoversService outage or disruptionCustomer and partner exposure

What to do now

  1. Check whether your Accellion FTA version is FTA_9_12_370 or earlier (or not obviously FTA_9_12_380+).
  2. If you are on an affected version, plan an immediate upgrade to Accellion FTA FTA_9_12_380 (and later) using the vendor’s update instructions.
  3. Confirm after the upgrade that the system is running the fixed release (FTA_9_12_380+) and that updates took effect.
  4. If you cannot upgrade right away, contact your vendor/IT support to apply the vendor’s interim mitigations from the provided guidance, and restrict access while waiting for the patch.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:Nov 17, 2021
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 4 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2021-27101 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows