Vulnerability Description: CWE-312: Cleartext Storage of Sensitive Information
Software Version: < 4.8.5
NIST: https://nvd.nist.gov/vuln/detail/CVE-2021-31539
CVSv3: 5.5
Severity: Medium
Credits: Francesco Giordano, Massimiliano Brolli
Wowza Streaming Engine through 4.8.5 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
Figure 1: File permissions