A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.fatpipeinc.com/support/cve-list.php | vendor advisory |
https://www.ic3.gov/Media/News/2021/211117-2.pdf | exploit us government resource mitigation third party advisory |