Lucene search

K
nvd[email protected]NVD:CVE-2021-20145
HistoryDec 09, 2021 - 4:15 p.m.

CVE-2021-20145

2021-12-0916:15:08
CWE-287
web.nvd.nist.gov
6
gryphon tower
routers
vulnerability
openvpn configuration
attackers
homebound vpn
lan interfaces
devices
network

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

68.6%

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users’ devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims’ devices as though they were on an adjacent network.

Affected configurations

Nvd
Node
gryphonconnectgryphon_tower_firmwareRange04.0004.12
AND
gryphonconnectgryphon_towerMatch-
VendorProductVersionCPE
gryphonconnectgryphon_tower_firmware*cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:*
gryphonconnectgryphon_tower-cpe:2.3:h:gryphonconnect:gryphon_tower:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

68.6%

Related for NVD:CVE-2021-20145