FatPipe是美国FatPipe公司的一种 WAN 冗余技术,它为公司提供自动和动态故障转移,因为广域网组件或服务故障导致数据线连接中断。 FatPipe WARP, IPVPN和MPVPN 10.1.2r60p91 和 10.2.2r42之前版本存在安全漏洞,该漏洞源于软件的web管理界面中缺少授权。攻击者可利用该漏洞访问URL“/fpui/jsp/index.jsp”,从而导致未知影响,可能违反了保密性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain a missing authorization caused by lack of access control in the web management interface, letting remote attackers access sensitive URLs, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27858.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-27856 | 9.8 CRITICAL | FatPipe software administrative account with no password |
| CVE-2021-27855 | 8.8 HIGH | FatPipe software allows privilege escalation |
| CVE-2021-27859 | 8.8 HIGH | Missing authorization vulnerability in FatPipe software |
| CVE-2021-27857 | 7.5 HIGH | FatPipe software allows unauthenticated configuration download |
No comments yet