Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. The pairing attempt fails due to the incorrect PIN, but the certificate from the forged pairing attempt is incorrectly persisted prior to the completion of the pairing request. This allows access to the certificate belonging to the attacker.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Sep 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lizardbyte
Lizardbyte sunshine |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:lizardbyte:sunshine:2024-05-27:*:*:*:*:*:*:* | |
Vendors & Products |
Lizardbyte
Lizardbyte sunshine |
Tue, 10 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. The pairing attempt fails due to the incorrect PIN, but the certificate from the forged pairing attempt is incorrectly persisted prior to the completion of the pairing request. This allows access to the certificate belonging to the attacker. | |
Title | Sunshine has incorrect state management during pairing process may lead to incorrectly authorized client | |
Weaknesses | CWE-300 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-10T15:13:20.126Z
Updated: 2024-09-10T16:12:18.563Z
Reserved: 2024-08-28T20:21:32.804Z
Link: CVE-2024-45407
Vulnrichment
Updated: 2024-09-10T16:12:13.526Z
NVD
Status : Analyzed
Published: 2024-09-10T16:15:20.617
Modified: 2024-09-20T16:18:46.717
Link: CVE-2024-45407
Redhat
No data.