PT-2020-14851 · Winston · Winston

Chris Davis

·

Published

2020-10-28

·

Updated

2020-11-04

·

CVE-2020-16260

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Winston version 1.5.4
Description The issue concerns a lack of authorization enforcement in the affected devices. This can be exploited from within the intranet and potentially combined with other vulnerabilities to achieve remote exploitation.
Recommendations For Winston version 1.5.4, consider implementing strict authorization controls to mitigate the risk of exploitation. As a temporary workaround, restrict access to sensitive areas of the device from the intranet to minimize the risk of unauthorized access.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16260

Affected Products

Winston