{"cvss":9.8,"datePublished":"2022-01-10","dateUpdated":"2022-01-10","description":"A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.","dueDate":"2022-01-24","id":"CVE-2021-27860","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-27860","product":"WARP, IPVPN, and MPVPN software","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit","vendor":"FatPipe"}