Known Vulnerabilities for products from Winstonprivacy
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Winstonprivacy".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Winstonprivacy can be found at device.report : Winstonprivacy
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-16263 json | Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by ... | 9.1 - CRITICAL | 2020-10-28 | 2020-11-03 |
| CVE-2020-16262 json | Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. | 7.8 - HIGH | 2020-10-28 | 2021-07-21 |
| CVE-2020-16261 json | Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. | 6.8 - MEDIUM | 2020-10-28 | 2021-07-21 |
| CVE-2020-16260 json | Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vul... | 7.5 - HIGH | 2020-10-28 | 2020-11-04 |
| CVE-2020-16259 json | Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and i... | 9.8 - CRITICAL | 2020-10-28 | 2021-07-21 |
| CVE-2020-16258 json | Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with defau... | 7.1 - HIGH | 2020-10-28 | 2020-11-04 |
| CVE-2020-16257 json | Winston 1.5.4 devices are vulnerable to command injection via the API. | 9.8 - CRITICAL | 2020-10-28 | 2021-07-21 |
| CVE-2020-16256 json | The API on Winston 1.5.4 devices is vulnerable to CSRF. | 8.8 - HIGH | 2020-10-28 | 2020-11-03 |
Known software with vulnerabilities from Winstonprivacy
| Type | Vendor | Product | Version |
|---|---|---|---|
| Hardware | Winstonprivacy | Winston | - |
| Operating System | Winstonprivacy | Winston Firmware | 1.5.4 |