Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Winston Firmware CRITICAL 9.8
CVE-2020-16259

Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the u…

No fix yet
Fix from $2,300 2020-10-28
Winston Firmware CRITICAL 9.1
CVE-2020-16263

Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.

No fix yet
Fix from $2,300 2020-10-28
Winston Firmware HIGH 7.8
CVE-2020-16262

Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.

No fix yet
Fix from $1,950 2020-10-28
Winston Firmware HIGH 7.5
CVE-2020-16260

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote …

No fix yet
Fix from $1,950 2020-10-28
Winston Firmware MEDIUM 6.8
CVE-2020-16261

Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.

No fix yet
Fix from $1,600 2020-10-28
Winston Firmware HIGH 8.8
CVE-2020-16256

The API on Winston 1.5.4 devices is vulnerable to CSRF.

No fix yet
Fix from $1,950 2020-10-28
Winston Firmware HIGH 7.1
CVE-2020-16258

Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

No fix yet
Fix from $1,950 2020-10-28
Winston Firmware CRITICAL 9.8
CVE-2020-16257

Winston 1.5.4 devices are vulnerable to command injection via the API.

No fix yet
Fix from $2,300 2020-10-28