CVE-2021-31539: Medium severity wowza streaming engine vulnerability
Published Apr 23, 2021
·Updated
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
Affected Software
1 affected component
Wowza Streaming Engine<4.8.8.01
Event History
Apr 23, 2021
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Wowza Streaming Engine vulnerability?
The vulnerability ID for this Wowza Streaming Engine vulnerability is CVE-2021-31539.
2
What is the severity of CVE-2021-31539?
CVE-2021-31539 has a severity rating of 5.5 (medium).
3
What is the affected software for CVE-2021-31539?
The affected software for CVE-2021-31539 is Wowza Streaming Engine before version 4.8.8.01 in a default installation.
4
Where are the cleartext passwords stored in this vulnerability?
In this vulnerability, cleartext passwords are stored in the conf/admin.password file.
5
Who can read the usernames and passwords in this vulnerability?
A regular local user is able to read usernames and passwords in this vulnerability.