Winstonprivacy

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    3
    Critical Level Threats
    4
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-16259

    Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.

    Last Modified: Nov 21, 2024
    Published: Oct 28, 2020

    CVE-2020-16258

    Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

    Last Modified: Nov 21, 2024
    Published: Oct 28, 2020

    CVE-2020-16260

    Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

    Last Modified: Nov 21, 2024
    Published: Oct 28, 2020

    CVE-2020-16263

    Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.

    Last Modified: Nov 21, 2024
    Published: Oct 28, 2020

    CVE-2020-16262

    Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.

    Last Modified: Nov 21, 2024
    Published: Oct 28, 2020
    Items Per Page