10
CVE-2021-20146
- EPSS 1.49%
- Veröffentlicht 09.12.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:00
- Quelle vulnreport@tenable.com
- CVE-Watchlists
- Unerledigt
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gryphonconnect ≫ Gryphon Tower Firmware Version <= 04.0004.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.49% | 0.793 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.