Vulnerabilities (CVE)

Filtered by vendor Winstonprivacy Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-16257 1 Winstonprivacy 2 Winston, Winston Firmware 2021-07-21 10.0 HIGH 9.8 CRITICAL
Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-16259 1 Winstonprivacy 2 Winston, Winston Firmware 2021-07-21 10.0 HIGH 9.8 CRITICAL
Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.
CVE-2020-16263 1 Winstonprivacy 2 Winston, Winston Firmware 2020-11-03 6.4 MEDIUM 9.1 CRITICAL
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.