CVE-2021-27857 Information
Description
A missing authorization vulnerability in the web management interface of FatPipe WARP IPVPN and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA003.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://www.zeroscience.mk/codes/fatpipe_configdl.txt https://www.fatpipeinc.com/support/cve-list.php https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5683.php
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: