|
209561
|
9.8 |
CRITICAL
Network
|
saltstack debian fedoraproject
|
salt debian_linux fedora
|
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
|
CWE-78
OS Command
|
CVE-2020-16846
|
2024-11-21 14:07 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209562
|
9.1 |
CRITICAL
Network
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-16263
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209563
|
7.8 |
HIGH
Local
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
|
CWE-269
Improper Privilege Management
|
CVE-2020-16262
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209564
|
6.8 |
MEDIUM
Physics
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
|
CWE-284
Improper Access Control
|
CVE-2020-16261
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209565
|
7.5 |
HIGH
Network
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.
|
CWE-862
Missing Authorization
|
CVE-2020-16260
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209566
|
9.8 |
CRITICAL
Network
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.
|
NVD-CWE-noinfo
|
CVE-2020-16259
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209567
|
7.1 |
HIGH
Local
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-16258
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209568
|
8.8 |
HIGH
Network
|
winstonprivacy
|
winston_firmware
|
The API on Winston 1.5.4 devices is vulnerable to CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-16256
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209569
|
9.8 |
CRITICAL
Network
|
winstonprivacy
|
winston_firmware
|
Winston 1.5.4 devices are vulnerable to command injection via the API.
|
CWE-78
OS Command
|
CVE-2020-16257
|
2024-11-21 14:07 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209570
|
7.5 |
HIGH
Network
|
arista
|
eos
|
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DH…
|
NVD-CWE-noinfo
|
CVE-2020-17355
|
2024-11-21 14:07 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|