CVE-2021-20146
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.
Affected (1)
Products: Gryphonconnect: Gryphon Tower Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 04.0004.12 |
| Running on/with | Platform Versions |
|---|---|
Gryphonconnect Gryphon Tower | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.