CVE-2019-19455
Last modified
CVE-2019-19455 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza Streaming Engine 4.8.5.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza Streaming Engine 4.8.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wowza | Streaming Engine | < 4.8.5 |
References
- https://www.gruppotim.it/redteamThird Party Advisory
- https://www.wowza.com/docs/wowza-streaming-engine-4-8-5-release-notesRelease Notes, Vendor Advisory
- https://www.gruppotim.it/redteamThird Party Advisory
- https://www.wowza.com/docs/wowza-streaming-engine-4-8-5-release-notesRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19455?
How severe is CVE-2019-19455?
How do I fix CVE-2019-19455?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1945Multiple vulnerabilities in the smart tunnel functionality o…6.7
- CVE-2019-19450paraparser in ReportLab before 3.5.31 allows remote code exe…9.8
- CVE-2019-19451When GNOME Dia before 2019-11-27 is launched with a filename…5.5
- CVE-2019-19452A buffer overflow was found in Patriot Viper RGB through 1.1…7.8
- CVE-2019-19453Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2…5.4
- CVE-2019-19454An arbitrary file download was found in the "Download Log" f…7.5
- CVE-2019-19456A Reflected XSS was found in the server selection box inside…6.1
- CVE-2019-19457SALTO ProAccess SPACE 5.4.3.0 allows XSS.5.4
- CVE-2019-19458SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in …8.6
- CVE-2019-19459An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An…9.8
- CVE-2019-1946A vulnerability in the web-based management interface of Cis…6.5
- CVE-2019-19460An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. Th…5.5
Are you affected by CVE-2019-19455?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
