ZeroHour

CVE-2021-27860

KEV PoC moderate

Unauthenticated Arbitrary File Upload in FatPipe WARP, IPVPN, and MPVPN

CISA: FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

CVSS 3.1
8.8 high
EPSS
40%p99
Published
()
KEV added
AI analysis

CVE-2021-27860 is an unrestricted file upload flaw (CWE-434) in the web management interface of FatPipe WARP, IPVPN, and MPVPN appliances, allowing a remote, unauthenticated attacker to upload a file to any location on the device's filesystem. It is triggered simply by sending an upload request to the exposed management interface, with no credentials required. An attacker who abuses it can place files anywhere on the appliance, which can be used to tamper with device configurations or plant files that may enable further compromise or code execution. Any organization running an internet-exposed FatPipe WARP, IPVPN, or MPVPN device — typically deployed as edge/SD-WAN and WAN failover appliances at enterprise and branch sites — is affected. The flaw is confirmed exploited in the wild (added to CISA KEV on 2022-01-10), carries a high EPSS of 39.8% (99th percentile) for near-term exploitation, and while no public PoC is known, ransomware involvement is listed as unknown.

What to do: Apply updates per vendor instructions, as required by CISA's KEV listing, since no specific fixed version numbers are provided in this data. In the interim, restrict access to the FatPipe web management interface with firewall rules or ACLs so it is not reachable from the internet. Check exposed devices for unexpected or recently modified files and configuration changes, given the unknown possibility of ransomware-related abuse.

Affected
FatPipe WARP software
FatPipe IPVPN software
FatPipe MPVPN software
Estimated exposure
moderatelikely on the order of thousands to low tens of thousands of internet-exposed FatPipe appliances (estimate; no public scan count provided) — FatPipe is a niche enterprise WAN/SD-WAN edge vendor whose WARP/IPVPN/MPVPN appliances are commonly deployed at corporate and branch network perimeters, where public internet scans of such appliances historically reveal only low thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

CISA Known Exploited Vulnerability
Affected
FatPipe WARP, IPVPN, and MPVPN software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
fatpipeinc
Products
ipvpn firmware, warp firmware, mpvpn firmware
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news