Winstonprivacy
8 CVEs tracked since 2020. Since Oct 2020, none of them reached CISA KEV.
Winstonprivacy CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-10 | 8 | 0 |
Products
The products that kept showing up in Winstonprivacy's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 8 most recently published vulnerabilities affecting Winstonprivacy.
- CVE-2020-16259Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.9.8
- CVE-2020-16258Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.7.1
- CVE-2020-16260Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.7.5
- CVE-2020-16263Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.9.1
- CVE-2020-16262Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.7.8
- CVE-2020-16261Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.6.8
- CVE-2020-16256The API on Winston 1.5.4 devices is vulnerable to CSRF.8.8
- CVE-2020-16257Winston 1.5.4 devices are vulnerable to command injection via the API.9.8
The record
- Peak rank
- #55 in Oct 2020
- Busiest month shown
- Oct 2020, 8 CVEs
- Months with a KEV entry
- 0 since Oct 2020
- Monthly snapshots
- 1 since 2020