6.4
CVSSv2

CVE-2020-16263

Published: 28/10/2020 Updated: 03/11/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

winstonprivacy winston firmware 1.5.4