Record summary

CVE-2021-27858 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List10.1 to < 10.1.2r60p91affected
10.2 to < 10.2.2r42affected
CVE List10.1 to < 10.1.2r60p91affected
10.2 to < 10.2.2r42affected
CVE List10.1 to < 10.1.2r60p91affected
10.2 to < 10.2.2r42affected

Nuclei templates

1
ProjectDiscoveryMEDIUMFatPipe WARP/IPVPN/MPVPN - Authorization BypassCVSS 5.3

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain a missing authorization caused by lack of access control in the web management interface, letting remote attackers access sensitive URLs, exploit requires no authentication.

Impact

Unauthenticated attackers can access sensitive management interface URLs and obtain device information due to missing authorization checks.

Remediation

Upgrade to FatPipe WARP/IPVPN/MPVPN version 10.1.2r60p91 or 10.2.2r42 or later.

WeaknessesCWE-862
Authorsgy741
Template tagscvecve2021fatpipeauth-bypassroutervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:o:fatpipeinc:warp_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4