CVE-2021-27858
Missing authorization vulnerability in FatPipe software
Record summary
CVE-2021-27858 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 10.1 to < 10.1.2r60p91 | affected | |
| 10.2 to < 10.2.2r42 | affected | ||
| CVE List | 10.1 to < 10.1.2r60p91 | affected | |
| 10.2 to < 10.2.2r42 | affected | ||
| CVE List | 10.1 to < 10.1.2r60p91 | affected | |
| 10.2 to < 10.2.2r42 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMFatPipe WARP/IPVPN/MPVPN - Authorization BypassCVSS 5.3
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain a missing authorization caused by lack of access control in the web management interface, letting remote attackers access sensitive URLs, exploit requires no authentication.
Impact
Unauthenticated attackers can access sensitive management interface URLs and obtain device information due to missing authorization checks.
Remediation
Upgrade to FatPipe WARP/IPVPN/MPVPN version 10.1.2r60p91 or 10.2.2r42 or later.
Source: ProjectDiscovery