Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgrc-fpr7-mq3c

Опубликовано: 10 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

EPSS

Процентиль: 52%
0.00286
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

EPSS

Процентиль: 52%
0.00286
Низкий

Дефекты

CWE-287