Vulnerability Details CVE-2021-31540
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application server configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.4%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 3.6
Products affected by CVE-2021-31540
-
cpe:2.3:a:wowza:streaming_engine:4.0.0
-
cpe:2.3:a:wowza:streaming_engine:4.0.1
-
cpe:2.3:a:wowza:streaming_engine:4.0.3
-
cpe:2.3:a:wowza:streaming_engine:4.0.4
-
cpe:2.3:a:wowza:streaming_engine:4.0.5
-
cpe:2.3:a:wowza:streaming_engine:4.0.6
-
cpe:2.3:a:wowza:streaming_engine:4.1.0
-
cpe:2.3:a:wowza:streaming_engine:4.1.1
-
cpe:2.3:a:wowza:streaming_engine:4.1.2
-
cpe:2.3:a:wowza:streaming_engine:4.2.0
-
cpe:2.3:a:wowza:streaming_engine:4.3.0
-
cpe:2.3:a:wowza:streaming_engine:4.4.0
-
cpe:2.3:a:wowza:streaming_engine:4.4.1
-
cpe:2.3:a:wowza:streaming_engine:4.5.0
-
cpe:2.3:a:wowza:streaming_engine:4.6.0
-
cpe:2.3:a:wowza:streaming_engine:4.7.0
-
cpe:2.3:a:wowza:streaming_engine:4.7.1
-
cpe:2.3:a:wowza:streaming_engine:4.7.3
-
cpe:2.3:a:wowza:streaming_engine:4.7.4
-
cpe:2.3:a:wowza:streaming_engine:4.7.4.0.1
-
cpe:2.3:a:wowza:streaming_engine:4.7.5
-
cpe:2.3:a:wowza:streaming_engine:4.7.6
-
cpe:2.3:a:wowza:streaming_engine:4.7.7
-
cpe:2.3:a:wowza:streaming_engine:4.7.8
-
cpe:2.3:a:wowza:streaming_engine:4.8.0
-
cpe:2.3:a:wowza:streaming_engine:4.8.5