Back to Database
Status published
Critical
CVE-2019-5623
Accellion File Transfer Appliance Improper Neutralization of Special Elements used in a Command ('Command Injection')
Vulnerability Description
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-5623
Credits & Attribution
No credits recorded in the NVD database.
More from Accellion
View All →CVE-2019-5622
Accellion File Transfer Appliance Use of Hard-coded Credentials
Critical
9.8
CVE-2016-9500
The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to informaiton exposure
Medium
6.1
CVE-2016-9499
The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to cross-site scripting.
Medium
5.3
Affected Vendor
Accellion
View all reports →Affected Software
File Transfer Appliance
Vulnerable Versions:
FTA_8_0_540
Timeline
Official Publish:
April 29th, 2020
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H