← Back to browse · API

CVE-2021-27856

Severity
CRITICAL
CVSS
9.8
EPSS
0.05598
Risk score
41.16
CISA KEV
No
PoC
No
Published
2021-12-15
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-14594, GHSA-8235-WX5Q-8WRV
Products
FatPipe:IPVPN 10.1 <10.1.2r60p91, FatPipe:IPVPN 10.2 <10.2.2r42, FatPipe:MPVPN 10.1 <10.1.2r60p91, FatPipe:MPVPN 10.2 <10.2.2r42, FatPipe:WARP 10.1 <10.1.2r60p91, FatPipe:WARP 10.2 <10.2.2r42
Sources
euvd EUVD-2021-14594

Description

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.

References