Vulnerabilities > CVE-2020-16260 - Missing Authorization vulnerability in Winstonprivacy Winston Firmware 1.5.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
winstonprivacy
CWE-862

Summary

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

Vulnerable Configurations

Part Description Count
OS
Winstonprivacy
1
Hardware
Winstonprivacy
1

Common Weakness Enumeration (CWE)