SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5109

The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.

MEDIUM 5.0EPSS 2.31%

Does this matter?

Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.

Description

The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.31% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-16
Affected
adobe/flash media server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.