CVE-2024-52056 Vulnerability Details

  /     /     /  

CVE-2024-52056 Metadata Quick Info

CVE Published: 21/11/2024 | CVE Updated: 21/11/2024 | CVE Year: 2024
Source: rapid7 | Vendor: Wowza | Product: Streaming Engine
Status : PUBLISHED

CVE-2024-52056 Description

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-22
CWE Name: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ( Path Traversal )
Source: Wowza

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-139
CAPEC Description: CAPEC-139 Relative Path Traversal


Source: NVD (National Vulnerability Database).