Winstonprivacy
Winstonprivacy Winston Firmware: vulnerabilidades y CVE
Winstonprivacy Winston Firmware tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-16263 | Crítica (9.1) | 1.2% | — | 28 oct 2020 | Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins. |
| CVE-2020-16262 | Alta (7.8) | 0.43% | — | 28 oct 2020 | Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. |
| CVE-2020-16261 | Media (6.8) | 0.47% | — | 28 oct 2020 | Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. |
| CVE-2020-16260 | Alta (7.5) | 0.93% | — | 28 oct 2020 | Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation. |
| CVE-2020-16259 | Crítica (9.8) | 1.8% | — | 28 oct 2020 | Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user. |
| CVE-2020-16258 | Alta (7.1) | 0.39% | — | 28 oct 2020 | Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. |
| CVE-2020-16256 | Alta (8.8) | 0.66% | — | 28 oct 2020 | The API on Winston 1.5.4 devices is vulnerable to CSRF. |
| CVE-2020-16257 | Crítica (9.8) | 3.7% | — | 28 oct 2020 | Winston 1.5.4 devices are vulnerable to command injection via the API. |