CVE-2024-34454

Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature (and because * is accepted as a Common Name).
Configurations

No configuration.

History

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://github.com/PretendoNetwork/SSSL - () https://github.com/PretendoNetwork/SSSL -
References () https://github.com/PretendoNetwork/SSSL-DNS - () https://github.com/PretendoNetwork/SSSL-DNS -

03 Jul 2024, 02:00

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

28 May 2024, 12:39

Type Values Removed Values Added
Summary
  • (es) Nintendo Wii U OS 5.5.5 permite a los atacantes intermediarios falsificar certificados SSL como si vinieran de una CA raíz, porque existe un mecanismo de verificación secundario que solo verifica si se conoce una CA e ignora los detalles de la CA y firma (y porque * se acepta como nombre común).

26 May 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-26 22:15

Updated : 2024-11-21 09:18


NVD link : CVE-2024-34454

Mitre link : CVE-2024-34454

CVE.ORG link : CVE-2024-34454


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management