PT-2021-19414 · Wowza · Wowza Streaming Engine
Francesco Giordano
+1
·
Published
2021-04-23
·
Updated
2021-12-03
·
CVE-2021-31540
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Wowza Streaming Engine versions through 4.8.5
Description
The issue concerns incorrect file permissions of configuration files in the conf/ directory. A regular local user can read and write to all the configuration files, allowing them to modify the application server configuration.
Recommendations
For Wowza Streaming Engine versions through 4.8.5, update the file permissions of the configuration files in the conf/ directory to restrict access to authorized users only.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wowza Streaming Engine