---
cve: "CVE-2019-5623"
severity: "LOW"
cvss: 3.1
epss: "1.6%"
vendor: "Accellion"
kev: false
exploited: false
published: "2020-04-29 23:15:13"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T15:41:05+02:00"
---

# CVE-2019-5623

> 3.1 LOW

## Beschreibung

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').

## Schwachstellen-Klasse

- **CWE-77** — Improper Neutralization of Special Elements used in a Command ('Command Injection')
  The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

## Angriffsmuster (CAPEC)

- [CAPEC-15 — Command Delimiters](https://capec.mitre.org/data/definitions/15.html) _(Severity: High)_
- [CAPEC-40 — Manipulating Writeable Terminal Devices](https://capec.mitre.org/data/definitions/40.html) _(Severity: Very High)_
- [CAPEC-43 — Exploiting Multiple Input Interpretation Layers](https://capec.mitre.org/data/definitions/43.html) _(Severity: High)_
- [CAPEC-75 — Manipulating Writeable Configuration Files](https://capec.mitre.org/data/definitions/75.html) _(Severity: Very High)_
- [CAPEC-76 — Manipulating Web Input to File System Calls](https://capec.mitre.org/data/definitions/76.html) _(Severity: Very High)_
- [CAPEC-136 — LDAP Injection](https://capec.mitre.org/data/definitions/136.html) _(Severity: High)_
- [CAPEC-183 — IMAP/SMTP Command Injection](https://capec.mitre.org/data/definitions/183.html) _(Severity: Medium)_
- [CAPEC-248 — Command Injection](https://capec.mitre.org/data/definitions/248.html) _(Severity: High)_

## Referenzen

- <https://www.rapid7.com/db/modules/exploit/linux/misc/accellion_fta_mpipe2>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-5623) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
