CVE-2020-9004
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges. This issue was resolved in Wowza Streaming Engine 4.8.5.
Una vulnerabilidad de omisión de autorización autenticada remota en Wowza Streaming Engine versión 4.8.0 y anteriores permite a cualquier usuario de sólo lectura emitir peticiones al panel de administración para cambiar la funcionalidad. Por ejemplo, un usuario de sólo lectura puede activar el puerto Java JMX en modo no autenticado y ejecutar comandos del Sistema Operativo con privilegios de root. Este problema se resolvió en Wowza Streaming Engine 4.8.5
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-16 CVE Reserved
- 2020-04-14 CVE Published
- 2023-05-18 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2020-9004.txt | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-9004-Authenticated%20Remote%20Authorization%20Bypass%20Leading%20to%20RCE-Wowza | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.wowza.com/docs/wowza-streaming-engine-4-8-5-release-notes | 2022-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wowza Search vendor "Wowza" | Streaming Engine Search vendor "Wowza" for product "Streaming Engine" | <= 4.8.0 Search vendor "Wowza" for product "Streaming Engine" and version " <= 4.8.0" | - |
Affected
|