CVE Feed

    Dashboard / CVE / CVE-2021-27860

    CVE-2021-27860

    A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

    Published:Dec 8, 2021
    Last Modified:Oct 24, 2025
    EPS:Dec 8, 2021
    EPSS Score:0.42561
    CVSS Score:9.8

    CISA Notification

    Description

    A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Jan 24, 2022
    1691 days ago
    Alert Date
    Jan 10, 2022
    1705 days ago

    Affected Products

    Vendor
    Fatpipeinc
    Product
    Ipvpn
    Vendor
    Fatpipeinc
    Product
    Ipvpn Firmware
    Vendor
    Fatpipeinc
    Product
    Mpvpn
    Vendor
    Fatpipeinc
    Product
    Mpvpn Firmware
    Vendor
    Fatpipeinc
    Product
    Warp
    Vendor
    Fatpipeinc
    Product
    Warp Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High