CISA Known Exploited Vulnerability

CVE-2021-27860

FatPipe · WARP, IPVPN, and MPVPN software

FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

Date added
BOD 22-01 due date
CWE CWE-434
Ransomware Unknown

CISA description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

Required action

Apply updates per vendor instructions.