CVE-2021-20129: High severity draytek vigorconnect vulnerability
Published Oct 13, 2021
·Updated
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
Affected Software
1 affected component
DrayTek VigorConnect=1.6.0-beta3
Event History
Oct 13, 2021
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20129?
The severity of CVE-2021-20129 is high with a CVSS score of 7.5.
2
What is the vulnerability description of CVE-2021-20129?
CVE-2021-20129 is an information disclosure vulnerability in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
3
How can an attacker exploit CVE-2021-20129?
An attacker can exploit CVE-2021-20129 by exploiting the information disclosure vulnerability in Draytek VigorConnect 1.6.0-B3 to export system logs.
4
Is authentication required to exploit CVE-2021-20129?
No, CVE-2021-20129 can be exploited by an unauthenticated attacker.
5
Is there a fix available for CVE-2021-20129?
At the moment, there is no known fix or patch available for CVE-2021-20129. It is recommended to monitor for vendor updates or security advisories.