7.2
CVSSv2

CVE-2020-16262

Published: 28/10/2020 Updated: 21/07/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

winstonprivacy winston_firmware 1.5.4