vendor:
WARP / IPVPN / MPVPN
by:
LiquidWorm
9,8
CVSS
CRITICAL
Unauthenticated Config Download
287
CWE
Product Name: WARP / IPVPN / MPVPN
Affected Version From: 5.2.0r34
Affected Version To: 10.2.2r38
Patch Exists: YES
Related CWE: CVE-2021-27092
CPE: a:fatpipe_networks:warp/ipvpn/mpvpn:10.2.2
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=148468, https://www.infosecmatter.com/nessus-plugin-library/?id=148461, https://www.infosecmatter.com/nessus-plugin-library/?id=149259, https://www.infosecmatter.com/nessus-plugin-library/?id=58141, https://www.infosecmatter.com/nessus-plugin-library/?id=35415, https://www.infosecmatter.com/nessus-plugin-library/?id=35419, https://www.infosecmatter.com/nessus-plugin-library/?id=107968
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2021
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Unauthenticated Config Download
A vulnerability in FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 allows an unauthenticated attacker to download the configuration file of the device. This can be done by sending a specially crafted HTTP request to the device. The configuration file contains sensitive information such as usernames, passwords, and IP addresses.
Mitigation:
Upgrade to the latest version of FatPipe Networks WARP/IPVPN/MPVPN.