Description
Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. The pairing attempt fails due to the incorrect PIN, but the certificate from the forged pairing attempt is incorrectly persisted prior to the completion of the pairing request. This allows access to the certificate belonging to the attacker.
INFO
Published Date :
2024-09-10T15:13:20.126Z
Last Modified :
2024-09-10T16:12:18.563Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2024-45407 vulnerability.
| Vendors | Products |
|---|---|
| Lizardbyte |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-45407.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact