CVE-2021-27860
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-01-10Remediation due 2022-01-24
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
9.8
CVSS
39.8%
EPSS (exploit prob.)
99th
EPSS percentile
2021-12-08
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fatpipeinc | ipvpn_firmware | 5.2.0 |
| fatpipeinc | ipvpn_firmware | 6.1.2 |
| fatpipeinc | ipvpn_firmware | 6.1.2 |
| fatpipeinc | ipvpn_firmware | 6.1.2 |
| fatpipeinc | ipvpn_firmware | 7.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 9.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.1.2 |
| fatpipeinc | ipvpn_firmware | 10.2.2 |
| fatpipeinc | ipvpn_firmware | 10.2.2 |
| fatpipeinc | ipvpn_firmware | 10.2.2 |
| fatpipeinc | ipvpn | all versions |
| fatpipeinc | warp_firmware | 5.2.0 |
| fatpipeinc | warp_firmware | 6.1.2 |
| fatpipeinc | warp_firmware | 6.1.2 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-27860