NVD disclosure day

Published threat advisories for February 16, 2021

CVE advisoryKnown Exploit

CVE-2021-27103

Accellion FTA SSRF Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Accellion FTA software versions prior to 9.12.416 are affected by a Server-Side Request Forgery vulnerability. This can allow an attacker to trick the system into making unintended requests, potentially exposing sensitive data or granting unauthorized system access. The realistic business risk includes data compromise,

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-27102

Accellion FTA OS Command Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Accellion FTA versions prior to 9.12.416 allow OS command execution through a local web service call. This vulnerability matters because unauthorized commands can be run on affected systems, posing a business risk of system compromise and potential data exfiltration.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-27101

Accellion FTA SQL Injection Vulnerability Advisory Title.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Accellion FTA is affected by a SQL injection vulnerability. Attackers can exploit this flaw by sending a crafted Host header, potentially leading to unauthorized access and modification of data. This presents a significant business risk to organizations using the affected software versions.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-21315

Systeminformation Command Injection Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A command injection vulnerability exists in the System Information Library for Node.js. This could allow an attacker with local access to execute unauthorized commands, impacting system integrity and data confidentiality. Organizations should identify and secure systems using this library.

• CISA KEV