LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-27860: FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-27860 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jan 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

CVE-2021-27860 is a vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software. It lets a remote attacker who has not authenticated upload a file to any location on the device filesystem. Because the management interface is often reachable from administrative networks—and sometimes more broadly—this class of flaw can give an attacker a direct path to place malicious content, alter configuration, or establish persistence on network appliances that sit in critical traffic paths. Defenders should treat exposure of these management interfaces as high priority and confirm all version and fix details against the vendor advisory.

How it works

The underlying weakness is CWE-434: unrestricted upload of a file with a dangerous type. In plain terms, the web management interface accepts a file upload without adequately restricting who may upload, what may be uploaded, or where the file may be written. An unauthenticated remote attacker can abuse that path to place a file anywhere on the filesystem.

Once an arbitrary file can be written, the practical impact depends on the appliance’s operating environment. Typical outcomes for this vulnerability class include overwriting configuration, dropping a web shell or other backdoor, or planting content that is later executed or loaded by a privileged process. The CISA summary does not publish exploit mechanics or proof-of-concept details; teams should not assume a particular payload and should instead focus on the fact that unauthenticated write-anywhere access to the filesystem is sufficient for full compromise of the device.

Am I affected? How to find it in your systems

FatPipe WARP, IPVPN, and MPVPN software is used in WAN optimization, VPN, and multi-path networking appliances. These devices commonly sit at branch or data-center edges and expose a web-based management interface for configuration.

How to remediate

Patching is the primary remediation. Apply the updates supplied by the vendor exactly as described in the vendor advisory and in accordance with CISA’s required action to “Apply updates per vendor instructions.” After upgrading, verify the running version matches the fixed release and re-check that the management interface no longer accepts unauthenticated uploads.

Beyond the patch, harden the management plane for this product class:

If you can't patch immediately

If an immediate upgrade is not possible, reduce exposure with compensating controls while you schedule the vendor update:

These steps only buy time; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities of this type frequently lead to device compromise and can be a stepping-stone into broader network access or data theft. Ransomware use specifically tied to this CVE is not documented in the supplied facts, but any successful filesystem write can still result in credential harvesting, traffic interception, or lateral movement. If you believe an appliance was exposed or exploited, isolate it, preserve logs and disk images for forensics, rotate any credentials or keys that resided on or traversed the device, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFatPipe · WARP, IPVPN, and MPVPN software
WeaknessCWE-434
Added to CISA KEVJan 10, 2022
Federal patch deadlineJan 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities