CVE-2021-27856
FatPipe software administrative account with no password
Record summary
CVE-2021-27856 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 5, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 10.1 to < 10.1.2r60p91 | affected | |
| 10.2 to < 10.2.2r42 | affected | ||
| CVE List | 10.1 to < 10.1.2r60p91 | affected | |
| 10.2 to < 10.2.2r42 | affected | ||
| CVE List | 10.1 to < 10.1.2r60p91 | affected | |
| 10.2 to < 10.2.2r42 | affected | ||
ipvpn_firmwareBrowse FatPipe / ipvpn_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALFatPipe WARP/IPVPN/MPVPN - Backdoor AccountCVSS 9.8
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain an account named "cmuser" with administrative privileges and no password, letting attackers gain unauthorized admin access, exploit requires no authentication.
Impact
Unauthenticated attackers can gain unauthorized administrative access via a backdoor account with no password, leading to complete device compromise.
Remediation
Upgrade to FatPipe WARP/IPVPN/MPVPN version 10.1.2r60p91 or 10.2.2r42 or later.
Source: ProjectDiscovery