Executive brief
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. This unrestricted file upload can lead to full system compromise.
Affected products
- FatPipe WARP prior to 10.1.2r60p92 and 10.2.2r44p1
- FatPipe IPVPN prior to 10.1.2r60p92 and 10.2.2r44p1
- FatPipe MPVPN prior to 10.1.2r60p92 and 10.2.2r44p1
Timeline
- 2021-11-17: disclosed: FBI/IC3 advisory released regarding exploitation
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-10: advisory: NVD publication date