PT-2020-14850 · Winston · Winston

Chris Davis

·

Published

2020-10-28

·

Updated

2021-07-21

·

CVE-2020-16259

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Winston version 1.5.4
Description The issue concerns an undocumented SSH user account in Winston devices, which allows access from bastion hosts. This account is not mentioned in device documentation and its existence is not disclosed to users.
Recommendations For Winston version 1.5.4, consider restricting access to the undocumented SSH user account to minimize potential risks until a formal fix or documentation update is provided. As a temporary workaround, review and adjust device configurations to limit access from bastion hosts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-16259

Affected Products

Winston