CVE-2021-27858
15.12.2021, 20:15
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fatpipeinc | ipvpn_firmware | 5.2.0:r34 |
| fatpipeinc | ipvpn_firmware | 6.1.2:r70p26 |
| fatpipeinc | ipvpn_firmware | 6.1.2:r70p45-m |
| fatpipeinc | ipvpn_firmware | 6.1.2:r70p75-m |
| fatpipeinc | ipvpn_firmware | 7.1.2:r39 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r129 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r144 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r150 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r156 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p12 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p16 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p17 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p2 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p20 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p26 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r161p3 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r164 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r164p4 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r164p5 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r165 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r180p2 |
| fatpipeinc | ipvpn_firmware | 9.1.2:r185 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p10 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p13 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p32 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p35 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p45 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p55 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p58 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p58s1 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p65 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p71 |
| fatpipeinc | ipvpn_firmware | 10.1.2:r60p82 |
| fatpipeinc | ipvpn_firmware | 10.2.2:r10 |
| fatpipeinc | ipvpn_firmware | 10.2.2:r25 |
| fatpipeinc | ipvpn_firmware | 10.2.2:r38 |
| fatpipeinc | mpvpn_firmware | 5.2.0:r34 |
| fatpipeinc | mpvpn_firmware | 6.1.2:r70p26 |
| fatpipeinc | mpvpn_firmware | 6.1.2:r70p45-m |
| fatpipeinc | mpvpn_firmware | 6.1.2:r70p75-m |
| fatpipeinc | mpvpn_firmware | 7.1.2:r39 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r129 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r144 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r150 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r156 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p12 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p16 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p17 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p2 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p20 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p26 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r161p3 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r164 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r164p4 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r164p5 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r165 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r180p2 |
| fatpipeinc | mpvpn_firmware | 9.1.2:r185 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p10 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p13 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p32 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p35 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p45 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p55 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p58 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p58s1 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p65 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p71 |
| fatpipeinc | mpvpn_firmware | 10.1.2:r60p82 |
| fatpipeinc | mpvpn_firmware | 10.2.2:r10 |
| fatpipeinc | mpvpn_firmware | 10.2.2:r25 |
| fatpipeinc | mpvpn_firmware | 10.2.2:r38 |
| fatpipeinc | warp_firmware | 5.2.0:r34 |
| fatpipeinc | warp_firmware | 6.1.2:r70p26 |
| fatpipeinc | warp_firmware | 6.1.2:r70p45-m |
| fatpipeinc | warp_firmware | 6.1.2:r70p75-m |
| fatpipeinc | warp_firmware | 7.1.2:r39 |
| fatpipeinc | warp_firmware | 9.1.2:r129 |
| fatpipeinc | warp_firmware | 9.1.2:r144 |
| fatpipeinc | warp_firmware | 9.1.2:r150 |
| fatpipeinc | warp_firmware | 9.1.2:r156 |
| fatpipeinc | warp_firmware | 9.1.2:r161p12 |
| fatpipeinc | warp_firmware | 9.1.2:r161p16 |
| fatpipeinc | warp_firmware | 9.1.2:r161p17 |
| fatpipeinc | warp_firmware | 9.1.2:r161p2 |
| fatpipeinc | warp_firmware | 9.1.2:r161p20 |
| fatpipeinc | warp_firmware | 9.1.2:r161p26 |
| fatpipeinc | warp_firmware | 9.1.2:r161p3 |
| fatpipeinc | warp_firmware | 9.1.2:r164 |
| fatpipeinc | warp_firmware | 9.1.2:r164p4 |
| fatpipeinc | warp_firmware | 9.1.2:r164p5 |
| fatpipeinc | warp_firmware | 9.1.2:r165 |
| fatpipeinc | warp_firmware | 9.1.2:r180p2 |
| fatpipeinc | warp_firmware | 9.1.2:r185 |
| fatpipeinc | warp_firmware | 10.1.2:r60p10 |
| fatpipeinc | warp_firmware | 10.1.2:r60p13 |
| fatpipeinc | warp_firmware | 10.1.2:r60p32 |
| fatpipeinc | warp_firmware | 10.1.2:r60p35 |
| fatpipeinc | warp_firmware | 10.1.2:r60p45 |
| fatpipeinc | warp_firmware | 10.1.2:r60p55 |
| fatpipeinc | warp_firmware | 10.1.2:r60p58 |
| fatpipeinc | warp_firmware | 10.1.2:r60p58s1 |
| fatpipeinc | warp_firmware | 10.1.2:r60p65 |
| fatpipeinc | warp_firmware | 10.1.2:r60p71 |
| fatpipeinc | warp_firmware | 10.1.2:r60p82 |
| fatpipeinc | warp_firmware | 10.2.2:r10 |
| fatpipeinc | warp_firmware | 10.2.2:r25 |
| fatpipeinc | warp_firmware | 10.2.2:r38 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References