Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20145

Опубликовано: 09 дек. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:*
Версия до 04.0004.12 (включая)
cpe:2.3:h:gryphonconnect:gryphon_tower:-:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00286
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
около 4 лет назад

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

EPSS

Процентиль: 52%
0.00286
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287