An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2021-51 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-03T17:30:07.621Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20146

No data.

Status : Modified
Published: 2021-12-09T16:15:08.167
Modified: 2024-11-21T05:46:00.663
Link: CVE-2021-20146

No data.

No data.