CVE-2024-45407
Last modified
CVE-2024-45407 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. The pairing attempt fails due to the incorrect PIN, but the certificate from the forged pairing attempt is incorrectly persisted prior to the completion of the pairing request. This allows access to the certificate belonging to the attacker.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lizardbyte | Sunshine | 2024-05-27 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45407?
How severe is CVE-2024-45407?
How do I fix CVE-2024-45407?
Are you affected by CVE-2024-45407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
