Vulnerability Details CVE-2021-31540
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application server configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.2%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 3.6
Products affected by CVE-2021-31540
-
cpe:2.3:a:wowza:streaming_engine:4.0.0
-
cpe:2.3:a:wowza:streaming_engine:4.0.1
-
cpe:2.3:a:wowza:streaming_engine:4.0.3
-
cpe:2.3:a:wowza:streaming_engine:4.0.4
-
cpe:2.3:a:wowza:streaming_engine:4.0.5
-
cpe:2.3:a:wowza:streaming_engine:4.0.6
-
cpe:2.3:a:wowza:streaming_engine:4.1.0
-
cpe:2.3:a:wowza:streaming_engine:4.1.1
-
cpe:2.3:a:wowza:streaming_engine:4.1.2
-
cpe:2.3:a:wowza:streaming_engine:4.2.0
-
cpe:2.3:a:wowza:streaming_engine:4.3.0
-
cpe:2.3:a:wowza:streaming_engine:4.4.0
-
cpe:2.3:a:wowza:streaming_engine:4.4.1
-
cpe:2.3:a:wowza:streaming_engine:4.5.0
-
cpe:2.3:a:wowza:streaming_engine:4.6.0
-
cpe:2.3:a:wowza:streaming_engine:4.7.0
-
cpe:2.3:a:wowza:streaming_engine:4.7.1
-
cpe:2.3:a:wowza:streaming_engine:4.7.3
-
cpe:2.3:a:wowza:streaming_engine:4.7.4
-
cpe:2.3:a:wowza:streaming_engine:4.7.4.0.1
-
cpe:2.3:a:wowza:streaming_engine:4.7.5
-
cpe:2.3:a:wowza:streaming_engine:4.7.6
-
cpe:2.3:a:wowza:streaming_engine:4.7.7
-
cpe:2.3:a:wowza:streaming_engine:4.7.8
-
cpe:2.3:a:wowza:streaming_engine:4.8.0
-
cpe:2.3:a:wowza:streaming_engine:4.8.5