ZeroHour

CVE-2021-20146

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.

Vendors
gryphonconnect
Products
gryphon tower firmware
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.