PT-2021-19414 · Wowza · Wowza Streaming Engine

Francesco Giordano

+1

·

Published

2021-04-23

·

Updated

2021-12-03

·

CVE-2021-31540

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wowza Streaming Engine versions through 4.8.5
Description The issue concerns incorrect file permissions of configuration files in the conf/ directory. A regular local user can read and write to all the configuration files, allowing them to modify the application server configuration.
Recommendations For Wowza Streaming Engine versions through 4.8.5, update the file permissions of the configuration files in the conf/ directory to restrict access to authorized users only. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31540

Affected Products

Wowza Streaming Engine