CVE-2021-27859

HIGHCVSS 8.8/10EPSS 1.62%

Last modified

CVE-2021-27859 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. EPSS estimates a 1.62% chance of exploitation in the next 30 days.

Description

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. This does not appear to be a CSRF vulnerability. The FatPipe advisory identifier for this vulnerability is FPSA005.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.62%

72.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
FatpipeincIpvpn Firmware5.2.0R34
FatpipeincIpvpn Firmware6.1.2R70p26
FatpipeincIpvpn Firmware7.1.2R39
FatpipeincIpvpn Firmware9.1.2R129
FatpipeincIpvpn Firmware10.1.2R60p10
FatpipeincIpvpn Firmware10.2.2R10
FatpipeincMpvpn Firmware5.2.0R34
FatpipeincMpvpn Firmware6.1.2R70p26
FatpipeincMpvpn Firmware7.1.2R39
FatpipeincMpvpn Firmware9.1.2R129
FatpipeincMpvpn Firmware10.1.2R60p10
FatpipeincMpvpn Firmware10.2.2R10
FatpipeincWarp Firmware5.2.0R34
FatpipeincWarp Firmware6.1.2R70p26
FatpipeincWarp Firmware7.1.2R39
FatpipeincWarp Firmware9.1.2R129
FatpipeincWarp Firmware10.1.2R60p10
FatpipeincWarp Firmware10.2.2R10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27859?
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. This does not appear to be a CSRF vulnerability. The FatPipe advisory identifier for this vulnerability is FPSA005.
How severe is CVE-2021-27859?
CVE-2021-27859 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.62% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27859?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27859?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST