10
CVE-2020-16259
- EPSS 1.75%
- Veröffentlicht 28.10.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:07:02
- Erkennungen
Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Winstonprivacy ≫ Winston Firmware Version 1.5.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.75% | 0.755 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
https://labs.bishopfox.com/advisories/winston-privacy-version-1.5.4
https://winstonprivacy.com/