Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20146

Опубликовано: 09 дек. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:*
Версия до 04.0004.12 (включая)
cpe:2.3:h:gryphonconnect:gryphon_tower:-:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01493
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-522

Связанные уязвимости

github
около 4 лет назад

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.

EPSS

Процентиль: 81%
0.01493
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-522