SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27858

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown…

MEDIUM 5.3EPSS 2.70%

Does this matter?

Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.

Description

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.70% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
fatpipeinc/ipvpn firmware · fatpipeinc/mpvpn firmware · fatpipeinc/warp firmware
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.