CVE-2021-27860

HIGHCVSS 8.8/10Actively ExploitedEPSS 39.82%

Last modified

CVE-2021-27860 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.. CISA has confirmed active exploitation in the wild. EPSS estimates a 39.82% chance of exploitation in the next 30 days.

Description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
39.82%

98.4th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
FatpipeincIpvpn Firmware5.2.0R34
FatpipeincIpvpn Firmware6.1.2R70p26
FatpipeincIpvpn Firmware7.1.2R39
FatpipeincIpvpn Firmware9.1.2R129
FatpipeincIpvpn Firmware10.1.2R60p10
FatpipeincIpvpn Firmware10.2.2R10
FatpipeincWarp Firmware5.2.0R34
FatpipeincWarp Firmware6.1.2R70p26
FatpipeincWarp Firmware7.1.2R39
FatpipeincWarp Firmware9.1.2R129
FatpipeincWarp Firmware10.1.2R60p10
FatpipeincWarp Firmware10.2.2R10
FatpipeincMpvpn Firmware5.2.0R34
FatpipeincMpvpn Firmware6.1.2R70p26
FatpipeincMpvpn Firmware7.1.2R39
FatpipeincMpvpn Firmware9.1.2R129
FatpipeincMpvpn Firmware10.1.2R60p10
FatpipeincMpvpn Firmware10.2.2R10

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2021-27860?
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
How severe is CVE-2021-27860?
CVE-2021-27860 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 39.82% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2021-27860?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27860?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST