Vulnerability Details CVE-2020-16260
Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-16260
-
cpe:2.3:h:winstonprivacy:winston:-
-
cpe:2.3:o:winstonprivacy:winston_firmware:1.5.4