Vulnerabilities > Winstonprivacy

DATE CVE VULNERABILITY TITLE RISK
2020-10-28 CVE-2020-16263 Exposure of Resource to Wrong Sphere vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins.
network
low complexity
winstonprivacy CWE-668
critical
9.1
2020-10-28 CVE-2020-16262 Improper Privilege Management vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
local
low complexity
winstonprivacy CWE-269
7.8
2020-10-28 CVE-2020-16261 Improper Access Control vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
low complexity
winstonprivacy CWE-284
6.8
2020-10-28 CVE-2020-16260 Missing Authorization vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices do not enforce authorization.
network
low complexity
winstonprivacy CWE-862
7.5
2020-10-28 CVE-2020-16259 Unspecified vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices have an SSH user account with access from bastion hosts.
network
low complexity
winstonprivacy
critical
9.8
2020-10-28 CVE-2020-16258 Use of Hard-coded Credentials vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.
local
low complexity
winstonprivacy CWE-798
7.1
2020-10-28 CVE-2020-16256 Cross-Site Request Forgery (CSRF) vulnerability in Winstonprivacy Winston Firmware 1.5.4
The API on Winston 1.5.4 devices is vulnerable to CSRF.
network
low complexity
winstonprivacy CWE-352
8.8
2020-10-28 CVE-2020-16257 OS Command Injection vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices are vulnerable to command injection via the API.
network
low complexity
winstonprivacy CWE-78
critical
9.8