Arbitrary file upload in FatPipe Networks Inc. products - #VU58226
Published: November 18, 2021
Vulnerability identifier: #VU58226
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in the web management interface. A remote attacker can upload a malicious file and execute it on the server.
Note, the vulnerability is being actively exploited in the wild.
Affected software
WARP
MPVPN
IPVPN
MPVPN
IPVPN
Remediation
Install updates from vendor's website.
WARP - addressed in versions 10.1.2r60p93, 10.2.2r44p1
MPVPN - addressed in versions 10.1.2r60p93, 10.2.2r44p1
IPVPN - addressed in versions 10.1.2r60p93, 10.2.2r44p1
MPVPN - addressed in versions 10.1.2r60p93, 10.2.2r44p1
IPVPN - addressed in versions 10.1.2r60p93, 10.2.2r44p1