Back to Database
Status published
Critical
CVE-2015-2857
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to...
Vulnerability Description
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2857
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.com/files/132665/Accellion-FTA-getStatus-verify_oauth_token-Command-Execution.html
- http://www.rapid7.com/db/modules/exploit/linux/http/accellion_fta_getstatus_oauth
- https://community.rapid7.com/community/metasploit/blog/2015/07/10/r7-2015-08-accellion-file-transfer-appliance-vulnerabilities-cve-2015-2856-cve-2015-2857
- https://www.exploit-db.com/exploits/37597/
More from accellion
View All →CVE-2022-24110
Kiteworks MFT 7.5 may allow an unauthorized user to reset...
Medium
6.5
CVE-2021-31586
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform...
High
8.8
CVE-2021-31585
Accellion Kiteworks before 7.3.1 allows a user with Admin privileges...
Medium
6.7
CVE-2021-27731
Accellion FTA 9_12_432 and earlier is affected by stored XSS...
Medium
6.1
CVE-2021-27730
Accellion FTA 9_12_432 and earlier is affected by argument injection...
Critical
9.8
Affected Vendor
accellion
View all reports →Affected Software
file transfer appliance
Vulnerable Versions:
0
Timeline
Official Publish:
August 22nd, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.