ZeroHour

CVE-2020-16260

PoC
CVSS 3.1
7.5 high
EPSS
<1%p59
Published
()
Modified
Description

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

Vendors
winstonprivacy
Products
winston firmware
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.