EXPOSURES › CVE-2021-27860
CVE-2021-27860
HIGH ⌖ ON CISA KEV · EXPLOITEDFatPipe WARP, IPVPN, and MPVPN software allowed remote, unauthenticated attackers to upload files to any filesystem location via its web management interface.
The web management interface of FatPipe WARP, IPVPN, and MPVPN software contained a vulnerability enabling remote, unauthenticated file uploads to arbitrary filesystem locations. This failure exposes network infrastructure to arbitrary code execution and data exfiltration, directly impacting DIB organizations relying on these VPN solutions for secure remote access. Organizations must verify patch levels and restrict web management access to mitigate similar risks.
Shame score — A remote, unauthenticated file upload vulnerability in a widely deployed VPN product represents a severe, avoidable security failure that directly enables arbitrary code execution and data theft.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.