AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-20146

CRITICAL · CVSS 9.8 EPSS 1.99%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-12-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-20146
Severity
CRITICAL
CVSS
9.8
EPSS
1.99%

Original NVD Description

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.