Vulnerabilities > Winstonprivacy > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-10-28 | CVE-2020-16263 | Exposure of Resource to Wrong Sphere vulnerability in Winstonprivacy Winston Firmware 1.5.4 Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. | 9.1 |
2020-10-28 | CVE-2020-16259 | Unspecified vulnerability in Winstonprivacy Winston Firmware 1.5.4 Winston 1.5.4 devices have an SSH user account with access from bastion hosts. | 9.8 |
2020-10-28 | CVE-2020-16257 | OS Command Injection vulnerability in Winstonprivacy Winston Firmware 1.5.4 Winston 1.5.4 devices are vulnerable to command injection via the API. | 9.8 |